Add PAN-OS 9.0 issues

This commit is contained in:
2026-03-31 14:49:41 -05:00
parent 9a10566267
commit 6b9a798266
30 changed files with 8350 additions and 3 deletions
@@ -0,0 +1,265 @@
---
type: Addressed
product: PAN-OS
version: 9.0.0
---
## WF500-4811
Fixed an issue where WF-500 appliances displayed the wrong WildFire® content version (show system info) after a WildFire content update.
## PAN-109668
A security related fix was made to limit the amount of information returned from an API call error message.
## PAN-109124
A security-related fix was made to address an issue where you were unable to retrieve GlobalProtect™ cloud service threat packet captures from the Logging Service on Panorama™ M-Series and virtual appliances.
## PAN-109096
Fixed an issue where the firewall did not remove the **4 Byte AS Format** number when **Remove Private AS** is enabled.
## PAN-109003
Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) stopped responding during a local commit.
## PAN-107887
Fixed an issue where an API call did not return the details of the security policy when you added a service group.
## PAN-107779
Fixed an issue where Wildfire signature version information was no longer displayed after you activated a GlobalProtect client.
## PAN-107117
Fixed an issue where device administrators were unable to manually upload signature files (**Device** > **Dynamic Updates**) and the firewall displayed the following error message: Youneed superuser privileges to do that.
## PAN-106784
Fixed an issue where the firewall revealed password hashes in the web interface when changing administrator passwords.
## PAN-106721
Fixed an intermittent issue where a processor cache memory corruption caused a reload when the firewall freed packets from the buffer.
## PAN-106695
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where the Panorama management server enabled the administrator to clone a rule on the passive firewall.
## PAN-106331
Fixed an issue with multiple or overlapping custom URL categories where traffic matched the incorrect Security policy rule when the custom URL category was used in a Security policy rule with a URL filtering profile.
## PAN-106181
Fixed an issue where the **Cancel** option was removed to prevent access when you **Require Password Change on First Login** (**Device** > **Setup** > **Management**).
## PAN-106019
Fixed an issue where a process (routed) stopped responding when an incomplete command ran in the XML API.
## PAN-105849
A security-related fix was made to address an issue with the wf_curl.log file in WF-500 appliances (WildFire).
## PAN-105737
Fixed an issue where AUX ports remained in Down state after you upgraded to PAN-OS® 8.1.7.
## PAN-105684
Fixed as issue on a firewall in an HA active/passive configuration where OSPF and BGP running on an Aggregate Ethernet (AE) with LACP enabled took longer than expected after a failover.
## PAN-105040
Fixed an issue where the dataplane processor caused memory loss in the packet buffer pool.
## PAN-104623
Fixed an issue where a process (brdagent) printed QoS information messages in the brdagent.log file, which caused a missed heartbeat and the firewall to restart.
## PAN-104616
Fixed an issue where certificate imports failed when you used a backslash ( \ ) character in a password to export certificates.
## PAN-104578
```caveat
PA-800 Series firewalls only
```
Fixed an issue on a firewall in an HA active/passive configuration where the HA failover took longer than expected.
## PAN-104572
Fixed an issue on Panorama M-Series and virtual appliances where the configd.log file displayed schema error messages after you created an administrator role with context switch UI permissions enabled.
## PAN-104354
Fixed an issue on a firewall in an HA active/passive configuration where the passive firewall ran a configuration out of sync after a restart.
## PAN-104078
Fixed an issue where administrators could not successfully add conditional advertisements (**Network** > **Virtual Routers** > **<virtual-router>** > **BGP** > **Conditional Adv**) for BGP routing tables (changes were lost after commit).
## PAN-103863
Fixed an issue where the IPSec tunnel restart (**Network** > **IPSec Tunnels** > **IKE Info**) did not display properly on the web interface.
## PAN-103857
Fixed an issue on a firewall in an HA active/passive configuration where the suspended firewall processed traffic.
## PAN-103615
Fixed an issue where scheduled log exports failed on nonstandard ports.
## PAN-103192
Fixed an issue on a firewall where the Global Find for IPSec tunnels displayed incorrect search results.
## PAN-103061
Fixed an issue where special characters contained in the CLI comment field caused the process (devsrvr) to stop responding.
## PAN-103055
Fixed an issue where you were unable to filter Address Groups (**Objects** > **Address Groups**) by an address object name.
## PAN-102779
Fixed an issue on a PA-3000 Series firewall where multiple (all_pktproc) processes failed and caused the dataplane to stop responding.
## PAN-102526
Fixed an issue on Panorama M-Series and virtual appliances where disk quota edits failed and displayed the following error message: quota-settings -> disk-quota is invalid.
## PAN-102029
Fixed an issue on a firewall where the DNS resolution routed through the dataplane and configured with a service route, stopped responding when the management interface was not configured.
## PAN-101821
Fixed an issue where Referer was spelled incorrectly in the HTTP Headers section of the Detailed Log View (**Monitor** > **URL Filtering**).
## PAN-101451
Fixed an issue where SNMP queries displayed incorrect values.
## PAN-101391
Fixed an issue where the scheduled nightly custom report was not generated or emailed as expected.
## PAN-101365
Fixed an intermittent issue where the session ID did not clear when the session ID is set to 0.
## PAN-101294
Fixed an issue where administrators were allowed to create tunnel interfaces from the template stack.
## PAN-101068
Fixed an issue where the object identifier (OID) ifAdminStatus incorrectly displayed up when configured to down.
## PAN-100656
Fixed an issue Panorama M-Series and virtual appliances where duplicate entries in BGP redistribution configurations were not verified, which caused commits to fail.
## PAN-100464
Fixed an issue where the sub-interfaces and the configurations were deleted when you tried to override the subinterface of a template stack.
## PAN-100154
Fixed an issue where the default static route always became the active route and took precedence over a DHCP auto-created default route that was pointing to the same gateway regardless of the metrics or order of installation. With this fix, the firewall no longer installs the default static route in the FIB when the system has both a DHCP auto-created default route and a manually configured default static route pointing to the same gateway.
## PAN-100049
Fixed an issue on Panorama M-Series and virtual appliances where Push Scope Selection (**Commit** > **Push to Devices**) selected firewalls not in the hierarchy of the firewall you selected.
## PAN-99945
Fixed an issue on Panorama where the progress bar in the web interface stopped responding and did not display any status after sending a commit or activating an auth code even though the task completed successfully.
## PAN-99640
A security-related fix was made to address a denial of service (DoS) vulnerability in PAN-OS Linux Kernel (CVE-2017-8890).
## PAN-99551
Fixed an issue on a firewall in an HA active/passive configuration where the User-ID™ process stopped responding on the passive firewall when the system was managing a high number of (more than 30,000) active users.
## PAN-99447
```caveat
Virtual and M-Series Panorama appliances and Log Collectors only
```
") Fixed an issue where a Log Collector received logs destined for closed Elasticsearch (ES) indices, which caused indices to return failure messages and, when the issue persisted for more than a few hours, caused Log Collectors to disconnect and reconnect repeatedly when attempting (and failing) to process the re-queued logs.
## PAN-98130
Fixed an intermittent issue where the firewall allowed traffic based on an unmatched rule after a session rematch is triggered.
## PAN-98005
Fixed an issue where adding more than eight Log Collectors to a collector group caused the configuration (configd) process to stop responding.
## PAN-97848
Fixed an issue where if you deployed Panorama on KVM, it deployed in Legacy mode instead of Management Only mode even when meeting the minimum resource requirements for Management Only mode.
## PAN-97417
Fixed an issue where the loopback IP address redistributed to the Local RIB table instead of the Adj-RIBs-out table.
## PAN-96344
Fixed an issue on a firewall where TCP reset packets were sent even after you set the vulnerability profile action to drop the packets.
## PAN-96297
Fixed an issue where a process (useridd) stopped responding due to the syslog server messages not parsing with field identifiers.
## PAN-95445
```caveat
This fix requires the VMware NSX 2.0.4 or a later plugin.
```
Fixed an issue where VM-Series firewalls for NSX and firewalls in an NSX notify group (**Panorama** > **VMware NSX** > **Notify Group**) briefly dropped traffic while receiving dynamic address updates after the primary Panorama in a high availability (HA) configuration failed over.
## PAN-94486
Fixed an issue where the dataplane did not get a dynamic IP address assigned because the process (routed) did not release it.
## PAN-92725
Fixed an issue on the firewall and Panorama management server where the web interface became unresponsive because the (cord) process restarted after you configured multiple log forwarding destinations in a single forwarding rule for Correlation logs (**Device** > **Log Settings**).
## PAN-92485
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to set the MTU (**Network** > **Interfaces** > **Ethernet** > **<Interface>** > **Ethernet Interface** > **Advanced** > **Other Info**) value to more than 1460 bytes with Jumbo Frames enabled.
## PAN-91930
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to type in tunnel zone names in the Tunnel Source Zone (**Policies >** > **Pre Rules >** > **<rule-name>** > **Inspection** > **Security Options**) field.
## PAN-91499
Fixed an issue on a firewall where an address object FQDN resolution returned the IPv6 DNS record but did not return all associated -- IPv4 and IPv6 -- DNS records.
## PAN-91442
Fixed an issue where an external dynamic list with an invalid IPv6 address range caused commits to fail.
## PAN-82278
Fixed an issue where filtering did not work for Threat logs when you filtered for threat names that contained certain characters: single quotation (), double quotation (”), back slash (\), forward slash (/), backspace (\b), form feed (\f), new line (\n), carriage return (\r), and tab (\t).
## PAN-72861
Fixed an issue where when you configured a PA-5200 Series or PA-7000 Series firewall to perform tunnel-in-tunnel inspection, which includes GRE keep-alive packets (**Policies** > **Tunnel Inspection** > **<tunnel_inspection_rule>** > **Inspection** > **Inspect Options**), and ran the clear session all CLI command while traffic was traversing a tunnel, the firewall temporarily dropped tunneled packets.
@@ -0,0 +1,505 @@
---
type: Addressed
product: PAN-OS
version: 9.0.10
---
## PAN-152699
Fixed an issue where the firewall added a redundant 0\r\n packet while processing Clientless VPN traffic.
## PAN-151197
Fixed an issue where a process (authd) restarted when an administrator authenticated to the firewall with an Active Directory (AD) account. This issue occurred when LDAP was configured with FQDN, used DHCP instead of a static management IP address, and used the management interface to connect to the LDAP server.
## PAN-150172
Fixed an issue where dataplane processes restarted when attempting to access websites that had the NotBefore attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
## PAN-150170
```caveat
and PAN-149822
```
A fix was made to address an OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allowed authenticated administrators to disrupt system processes and execute arbitrary code and OS commands with root privileges ([CVE-2020-2000](https://security.paloaltonetworks.com/CVE-2020-2000)).
## PAN-150013
```caveat
and PAN-149822
```
A fix was made to address an OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allowed authenticated administrators to disrupt system processes and execute arbitrary code and OS commands with root privileges ([CVE-2020-2000](https://security.paloaltonetworks.com/CVE-2020-2000)).
## PAN-149839
```caveat
PA-7000 Series firewalls only
```
Added CLI commands to enable/disable resource-control groups and CLI commands to set an upper memory limit of 8G on a process (mgmtsrvr). To enable resource-control groups, use debug software resource-control enable and to disable them, use debug software resource-control disable. To set the memory limit, use debug management-server limit-memory enable, and to remove the limit, use debug management-server limit-memory disable. For the memory limit change to take effect, the firewall must be rebooted.
## PAN-149813
Fixed an issue where the reply to an XML API call from Panorama was in a different format after upgrading to PAN-OS 8.1.14-h1 and later releases, which caused automated systems to fail the API call.
## PAN-149325
Fixed an issue on Panorama where the web interface took more time than expected to load changes when the virtual router was large or when there was a large configuration change request from the web interface.
## PAN-149005
Fixed an issue where XML API failed to fetch logs larger than 10MB.
## PAN-148806
A fix was made to address an uncontrolled resource consumption vulnerability in PAN-OS that allowed for a remote unauthenticated user to upload temporary files through the management web interface that were not properly deleted after the request was finished. An attacker could disrupt the availability of the management web interface by repeatedly uploading files until available disk space was exhausted ([CVE-2020-2039](https://security.paloaltonetworks.com/CVE-2020-2039)).
## PAN-148676
Fixed an issue where the panlogs directory reached 100% utilization on the firewall due to early calculation of the .size file.
## PAN-148522
Fixed an issue for PAN-DB where certain situations caused performance issues.
## PAN-147996
```caveat
PA-7000b Series firewalls only
```
Fixed a buffer overflow issue.
## PAN-147424
Fixed an issue with internal buffer and file sizes where logs were discarded due to slow log purging when the incoming log rate was high.
## PAN-147399
Fixed an issue where Panorama in Legacy mode rebooted due to multiple process (reportd) restarts.
## PAN-147258
Fixed an issue with one-way audio for inbound voice calls due to incorrect source port translation.
## PAN-147203
Fixed an issue where API calls did not return the output for the operational command for running configurations.
## PAN-146837
A fix was made to address a vulnerability involving information exposure through log files where sensitive fields were recorded in the configuration log without masking on PAN-OS software when the after-change-detail custom syslog field was enabled for configuration logs and the sensitive field appeared multiple times in one log entry. The first instance of the sensitive field was masked but subsequent instances were left in clear text ([CVE-2020-2043](https://security.paloaltonetworks.com/CVE-2020-2043)).
## PAN-146624
Fixed an issue where exporting logs from the web interface did not generate a system log entry.
## PAN-145942
After upgrading to certain PAN-OS 8.1 and 9.0 versions, for certain configurations using dynamic routing without graceful restart and with Bidirectional Forwarding Detection (BFD) enabled, there was a longer traffic hit after a high availability (HA) failover compared to previous versions. This was due to BFD incorrectly timing admin-down messages for the failover event.
## PAN-145929
Fixed an issue where, after upgrading the passive firewall, the stream control transmission protocol (SCTP) sessions synced from the active firewall did not retain the rule information, and, after failover, SCTP stateful inspection did not work.
## PAN-145507
Fixed an issue on the firewalls where traffic originating from a GlobalProtect user did not match host information profile (HIP) based Security policies using the cached HIP report. Instead, the traffic was denied until the GlobalProtect agent submitted a new HIP report about 20 seconds later.
## PAN-145422
Fixed an issue where a process (all_pktproc) restarted while processing SSL VPN sessions.
## PAN-145305
Fixed an issue where an inconsistent PAN-DB cloud connection caused the firewall to negotiate the incorrect version and decode the cloud responses with the incorrect format.
## PAN-145302
Fixed an issue where the HA peer device did not preserve its import configuration when the mode was active/active and VR sync was disabled.
## PAN-145142
Fixed an issue where Panorama running 9.0.8 allowed a user with the admin role Device Group and Template to create templates and template stacks.
## PAN-145041
Fixed an issue on the firewalls where a process (all_task) stopped responding.
## PAN-144804
Fixed an issue where the firewall generated GPRS tunneling protocol (GTP) logs for invalid GTP packets. This fix also implements a counter, flow_gtp_invalid_ver, where the invalid packets are counted.
## PAN-144670
Fixed an issue where the multi-factor authentication (MFA) timestamp was not redistributed across the virtual system (vsys) when the IP address-to-user mapping type was UIA.
## PAN-144613
Fixed an issue where, when previewing device group configurations from Panorama, the following error message was returned: Parameter device group missing.
## PAN-144492
Fixed an issue where traffic matched an incorrect URL filtering profile due to a similarity in the MD5 hashes between the URL filtering profiles.
## PAN-144232
Fixed an issue where, when any change was made to an authentication profile, the LDAP server or local user database in a shared context removed the user group mapping information from the firewall.
## PAN-143686
Fixed an issue where a firewall running in FIPS mode was unable to download the GlobalProtect datafile even when a GlobalProtect license was installed and valid.
## PAN-143644
Fixed an issue in multi-vsys firewalls where traffic did not match an FQDN address group based policy.
## PAN-143493
Fixed an memory issue associated with a process (mgmtsrvr) due to a large number of ACK packets in logs on Panorama or the log collector.
## PAN-143442
Fixed an issue where Amazon Web Services (AWS) Nitro System based VM-Series firewalls unexpectedly rebooted due to input/output (I/O) errors caused by improper NMVE I/O timeout settings.
## PAN-142927
Fixed an issue where the locked users list grew too large, which caused 100% CPU usage on a process (authd). With this fix, locked users will be purged hourly if the lockout time for that user has expired.
## PAN-142853
Fixed an issue on Panorama where commits failed, referring to a portion of the configuration that was not changed.
## PAN-142674
Fixed an issue where a process (brdagent) failed in an HA configuration using High Speed Chassis Interconnect (HSCI) ports due to a memory leak.
## PAN-142363
Fixed an issue where a process (*mprelay*) stopped responding and invoked an out-of-memory (OOM) killer condition and displayed the following error messages: `tcam full` and `pan_plfm_fe_cp_arp_delete`.
## PAN-142302
Fixed an issue where the firewalls faced connection issues with Cortex Data Lake.
## PAN-142089
Fixed an internal logging issue for a daemon (authd).
## PAN-141844
Fixed an issue where promiscuous VLAN mode did not work with the new host drivers being used on the ESXi and single-root input/output virtualization (SR-IOV) with VLAN tagging did not work as expected. Both Data Plane Development Kit and packet mmap mode did not work.
## PAN-141239
Fixed an issue where dataplane free memory was depleted, which affected new GlobalProtect connections to the firewall.
## PAN-141221
Fixed an issue where a commit or content update operation with an error was not prevented from executing in the dataplane, which caused corruption in the dataplane policy cache.
## PAN-141099
Fixed an issue where the HTTP/2 stream method was no longer valid after overloading the same pointer to point to either the HTTP/2 stream or the proxy flow.
## PAN-140982
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where a process (mprelay) on the control plane was restarted due to an internal heartbeat miss.
## PAN-140747
Fixed an issue where the firewall failed to establish SFTP firewall-server connections when SSH decryption was enabled.
## PAN-140389
Fixed an issue on Panorama in Legacy mode where configuring Network File System (NFS) log storage (**Device > Setup > Operations**) caused all plugin installations to fail.
## PAN-140375
Fixed an issue where a process (logrcvr) exited due to a race condition.
## PAN-139365
```caveat
PA-7000 Series firewalls only
```
Enhanced latency-sensitive protocols processing. With this fix, the following latency-sensitive control traffic will be prioritized: BGP, BFD, LACP, OSPF, OSPFv3, Protocol Independent Multicast (PIM), and Internet Group Management Protocol (IGMP).
## PAN-139264
Fixed an issue where the Elasticsearch cluster status displayed in yellow due to a missing replica serial number.
## PAN-139172
Fixed an issue where response pages generated from the firewall used the SMAC and DMAC addresses from the original packet, which caused a MAC flap on connected switches.
## PAN-138584
Fixed an issue that prevented the addition of a secondary logging disk for a VM-Series firewall deployed on AWS using Nitro server instance types.
## PAN-138037
Fixed an issue where the host information profile (HIP) match message was automatically enabled when modifying the GlobalProtect Agent settings.
## PAN-138034
Fixed an issue where virtual machine (VM) information source Dynamic Address Groups overrode static address groups, which caused traffic to hit the wrong Security policy rule.
## PAN-137885
```caveat
VM-Series firewalls in Microsoft Azure environment only
```
Fixed an issue where a firewall with accelerated networking enabled was unable to process packets efficiently because of underlying Microsoft drivers. To leverage this fix, you must upgrade to VM-Series Plugin 1.0.12.
## PAN-137656
Fixed an issue where the show config diff CLI command did not work correctly and produced unexpected output.
## PAN-136957
Fixed an issue where access was denied if a password contained more than 63 characters.
## PAN-136950
Fixed an issue where, on a firewall managed by Panorama, the XML API based IP tags were lost after a firewall reboot or process (**useridd**) restart.
## PAN-136844
Fixed an issue for S11 traffic where if the Modify Bearer Request message came after 30 seconds of Create Session Response message, the firewall dropped the Modify Bearer Request packet. This fix increases this time to 90 seconds.
## PAN-136726
Fixed an issue on the firewall where the dataplane pan-task process (all_pktproc) stopped responding while inspecting Server Message Block (SMB) traffic.
## PAN-136623
Fixed an issue where a process (useridd) failed due to internal user groups that were loading from the disk taking over the lock.
## PAN-136304
Fixed an issue where clientless VPN rewrite failed due to incorrect parsing of the HTML webpage.
## PAN-135946
Fixed an intermittent issue where Panorama was unable to query logs from the log collector due to large file sizes in es_cache_cron.log.
## PAN-135547
Fixed an issue on Panorama where administrators were unable to delete a shared address object even when it was not referenced in the configuration.
## PAN-135418
Fixed an issue on the firewall where configuring uppercase **User Domain** values in authentication profiles led to a failure in GlobalProtect Agent configuration selection based on the domain user match condition.
## PAN-135356
Fixed an issue where policies that contained objects did not display correctly when exported to CSV or PDF format.
## PAN-135354
Fixed an issue where the paths between the control plane and the dataplanes in network processing cards (NPCs) stalled in the dataplane-to-control plane direction due to the Ring Descriptor entries becoming out of sync on each side. This produced unrecoverable data path monitoring failures, which caused the chassis to become nonfunctional.
## PAN-135321
Fixed an issue where all NAT rules using the same FQDN entries as translated IP addresses were not updated when the IP addresses changed for those FQDNs.
## PAN-135262
A fix was made to address a vulnerability involving information exposure through log files where an administrator's password or other sensitive information was logged in cleartext while using the CLI in PAN-OS software. The opcmdhistory.log file was introduced to track operational command (op-command) usage but did not mask all sensitive information ([CVE-2020-2044](https://security.paloaltonetworks.com/CVE-2020-2044)).
## PAN-135158
Fixed an issue where setting an IPv6 destination filter for the packet-diag option returned an error regarding a character limit.
## PAN-135134
Fixed an issue where using a session_proxy() without checking that it actually is a proxy led to a dataplane process restart.
## PAN-134981
Fixed an issue with a memory leak in a process (user-id) due to failed LDAP over SSL (LDAPS) requests.
## PAN-134810
Fixed an issue where **Resolve (Objects > Addresses > <Name>)** in the web interface did not work for FQDN address objects with more than 63 characters.
## PAN-134714
Fixed an issue where Safe Search was not enabled after an application change.
## PAN-134624
```caveat
VM-Series firewalls only
```
Fixed an issue where the VLAN interface failed to obtain the MAC address when the interface was used as a DHCP relay agent.
## PAN-134488
Fixed an issue where a process (all_pktproc) restarted while processing Clientless VPN traffic.
## PAN-134038
Fixed an issue where custom signatures did not properly detect the User-Agent header when the Origin header was above the User-Agent header.
## PAN-133915
Fixed an issue on Panorama where configuring a BGP import rule from the CLI failed with the following error message: Server error : permission denied for the command set.
## PAN-133912
Fixed an issue where querying traffic logs based on address objects and address groups did not work.
## PAN-133880
Fixed an issue where RADIUS authentication failed due to an FQDN resolution failure after the VM-Series firewall rebooted.
## PAN-133673
Fixed an issue that caused a procses (ikemgr) to exit when site-to-site VPNs experienced connectivity interruptions.
## PAN-133609
Fixed an issue where the Authentication Portal did not work due to a large number of HTTP requests with unsupported Authorization headers.
## PAN-133285
Fixed an issue on the firewalls where configuring a default Online Certificate Status Protocol (OCSP) URL in front of an intermediate certificate authority (CA) in a certificate profile did not override the OCSP URL during the validation of client certificates issued by the intermediate CA.
## PAN-132922
Fixed an issue where service objects were unable to be deleted if they were configured to exceed firewall limits.
## PAN-132715
Fixed an issue where a child dynamic address group was not added as a member of the parent group.
## PAN-132697
Fixed an issue where the GlobalProtect portal did not generate certificate signing requests (CSRs) due to failed Simple Certificate Enrollment Protocol (SCEP) authentication cookie validation.
## PAN-131973
Fixed an issue where both firewalls in an HA active/passive configuration stopped responding at the same time.
## PAN-131814
Fixed an issue where the firewall did not recognize a device when the DHCP contained a hostname with a trailing NULL.
## PAN-131491
Fixed an issue where the **ACC** risk meter displayed as zero for long time periods with a large amount of logs.
## PAN-131045
Fixed an issue where a rare cleartext HTTP/2 application behavior caused a resource leak. If jumbo frames were enabled, this leak caused the App-ID queue to fill up quickly, which led to legitimate sessions being discarded.
## PAN-130564
Fixed an issue where the session ID did not display correctly in the debug logs related to the hardware security module (HSM).
## PAN-130562
Fixed an issue where, in VM-Series firewalls deployed using init-cfg.txt in the bootstrap process and set in an HA configuration, the configuration did not display as synchronized due to the initcfg configuration.
## PAN-130168
Fixed an issue where a process (pan_comm) stopped responding due to operation commands run during a commit.
## PAN-129474
Fixed an issue where a process (mgmtsrvr) restarted due to race conditions initialized by the mutex.
## PAN-129461
Fixed an issue where excessive next hop FPGA exceptions occurred when an ARP request or response was lost in the network in an ECMP configuration, which blocked subsequent ARP learning due to a full queue.
## PAN-129294
Fixed an issue on Panorama where the **Policy Optimizer** showed invalid data for **Rule Usage**.
## PAN-129277
Enhanced a daemon (dnsproxy) to support DNS compression for query strings.
## PAN-128761
A fix was made to address an OS command injection vulnerability in the PAN-OS management interface that allowed authenticated administrators to execute arbitrary OS commands with root privileges ([CVE-2020-2037](https://security.paloaltonetworks.com/CVE-2020-2037)).
## PAN-128650
Fixed an issue where selecting **Preview Changes** under a specific device group resulted in the following error message: Parameter device group missing.
## PAN-128042
Fixed an issue where the dynamic address group failed due to a process (devsrvr) not being synced with another process (useridd).
## PAN-127691
Fixed an issue where the dataplane maintained the old category for the URL even after changing or deleting that category from PAN-DB.
## PAN-126938
Fixed an issue where multiple daemons restarted due to MP ARP overflow.
## PAN-126353
Fixed an issue where the XML API used to retrieve hardware status periodically failed with a 200 OK message and no data.
## PAN-120530
Fixed an issue where a Panorama appliance running PAN-OS 10.0.0 observed restarts in a process (reportd) while running a custom report when the log collector or remote device was running a software version earlier than the current version on Panorama.
## PAN-120249
Fixed an issue where Elasticsearch failed to properly start up, which caused issues with logging on Panorama or the Log Collector.
## PAN-118468
```caveat
VM-Series firewalls on VMware ESXi only
```
Fixed an issue where the firewall stays in a boot loop and enters maintenance mode after adding a 60GB disk.
## PAN-118416
```caveat
Japanese language only
```
Fixed an issue where the **WildFire Update Schedule** incorrectly displayed At as Atlantic.
## PAN-116843
Fixed an issue on Panorama where, when navigating through **Policies**, the following error message displayed: show rule hit count op-command failed.
## PAN-115954
Fixed an issue where commits failed with the following error: Error unserializing profile objects failed to handle CONFIG_UPDATE_START.
## PAN-113523
Fixed an intermittent issue where configuration audit stopped showing commit history and revisions.
## PAN-112539
Fixed an issue where the firewall stopped forwarding logs to the log collector from the Log Processing Card (LPC) after a commit push from Panorama due to a race condition.
## PAN-112246
Fixed an issue on the firewalls where a process (mgmtsrvr) restarted after the Panorama connection flapped.
## PAN-101484
A fix was made to address an OS command injection vulnerability in the PAN-OS management interface that allowed authenticated administrators to execute arbitrary OS commands with root privileges ([CVE-2020-2038](https://security.paloaltonetworks.com/CVE-2020-2038)).
@@ -0,0 +1,257 @@
---
type: Addressed
product: PAN-OS
version: 9.0.12
---
## PAN-158691
Fixed an issue with GPRS tunneling protocol (GTP) event packet capture (pcap) where enabling **Packet Capture** did not work.
## PAN-155053
Fixed an issue where user information in the Clientless VPN wasn't handled properly in high availability (HA) configurations, which resulted in the firewall being unable to create more user sessions.
## PAN-154323
Fixed an issue in Panorama where frequent API requests caused the Panorama web interface to become unresponsive. This issue occurred because the web interface automatically refreshed after each request.
## PAN-154114
A fix was made to address a vulnerability related to information exposure through log files in PAN-OS where secrets in PAN-OS XML API requests were logged in cleartext in the web server logs when the API was used incorrectly ([CVE-2021-3036](https://security.paloaltonetworks.com/CVE-2021-3036)).
## PAN-153440
Fixed an issue where firewalls repeatedly connected and disconnected to Cortex Data Lake due to a probing issue.
## PAN-153107
Fixed an issue where a dataplane process stopped responding while processing fragmented traffic on GTP-U tunnels.
## PAN-152912
Fixed an issue where a content update caused the Panorama XML cache build to fail. This resulted references of the used objects on Panorama being removed, which caused commits on the managed firewalls to fail.
## PAN-152746
Fixed an issue where the firewall dropped GTPv2-x Create Session Response packets with the following error message: bad port 84b.
## PAN-152440
Fixed an issue where the syntax on GlobalProtect DNS suffixes was not validated.
## PAN-152282
Fixed an issue where platforms using AHO for content and application inspection ran into dataplane process (all_pktproc) restarts.
## PAN-151486
Fixed an issue where user activity reports failed to run when the firewall was in FIPS mode.
## PAN-151483
Fixed an issue where, when an out-of-order stream of TCP packets was subjected to HTTP header insertion, the packets were duplicated.
## PAN-151149
Fixed an issue where certificates, custom logos, and Security Assertion Markup Language (SAML) metadata were unable to be uploaded from the web interface using a Chromium-based browser running version 84 or later.
## PAN-149915
Fixed an issue where a Panorama virtual appliance was unable to manage more than 2,500 firewalls when 28 or more CPU cores were available.
## PAN-149696
Fixed an intermittent issue where the GlobalProtect portal stopped responding with a 502 Bad Gateway response page when trying to access the portal URL using a web browser.
## PAN-149645
Fixed an issue in a virtual wire deployment configured with **Link State Pass Through** enabled where, when one member port went down, the peer port took longer than expected to change the status to **Down**.
## PAN-149547
Fixed an issue where, after a change in Security policies, traffic logs for inner GTP-U sessions did not show IMSI or IMEI fields following a commit.
## PAN-149377
A fix was made to address a vulnerability regarding information exposure through log files in PAN-OS that made it possible for configuration secrets for HTTP, email, and SNMP trap v3 log forwarding server profiles to be logged to the logrcvr.log system log ([CVE-2021-3032](https://security.paloaltonetworks.com/CVE-2021-3032)).
## PAN-149001
Fixed an issue where, when using certificate profiles configured under specific virtual systems (vsys), the GlobalProtect **Machine Certification Check** and **HIP Object** fail during a client certificate check.
## PAN-148818
Fixed an issue where the decryption profile was configured without the **Block sessions with expired certificates** option, but the firewall still blocked websites that were signed by an Expired AddTrust Root CA (certificate authority).
## PAN-148767
Fixed an issue where the firewall incorrectly created GTP-U sessions from Create Session Request and Create Session Response packets.
## PAN-148441
Fixed an issue where required processes were not automatically restarted on the Log Processing Card (LPC) or the Log Forwarding Card (LFC).
## PAN-147847
Fixed an issue where traffic didn't hit the intended Security policy if SSL forward proxy was enabled and service was set to **application-default**.
## PAN-147796
Fixed an issue on the firewalls with an IPsec/Encapuslating Security Payload (ESP) traffic with GlobalProtect gateway configuration where multiple processes (flow_ctrl, pktlog_forwarding, and all_task) restarted, which caused the device to reboot.
## PAN-147529
Fixed an issue where **ValidateAll** jobs were incorrectly logged as **CommitAll** in the configuration log of the firewall.
## PAN-147385
Fixed an issue where firewall buffers were depleted with GTP traffic due to the mishandling of conflicting sessions.
## PAN-147305
Fixed an issue where a process (useridd) stopped responding to requests.
## PAN-147298
```caveat
PA-7050 and PA-7080 firewalls with 100G NPC only
```
Fixed an issue where jumbo frames brought down the Network Processing Card (NPC) when traffic traversed the firewall at a high rate.
## PAN-147036
Fixed an issue where TCP connections got stuck between the firewall and the Log Collector if some packets were dropped on the path between the two appliances.
## PAN-146763
Fixed a configuration issue on a multi-vsys where the configured interface service route for email schedule reports was not being used.
## PAN-146215
```caveat
FPP offload based hardware model only
```
Fixed an issue where, when UDP traffic that was received on a tunnel had back-to-back client-to-server packets, random packets dropped.
## PAN-145996
An update was made to change the following system log message: DO NOT CHOOSE WMI in Active-Directory FOR YOUR USE CASE IF SEE THIS LOG AGAIN IN <number> SECONDS to Please change server monitor(log server) Transport Protocol from WMI to WinRM for better performance. This update also reduces the severity from **High** to **Informational**.
## PAN-144410
Debug logs were added to detect an out-of-memory (OOM) condition that caused the management server to restart.
## PAN-143090
Fixed an issue where the firewall silently dropped TCP out-of-order packets.
## PAN-142867
Fixed an issue where service session timeout override was not used for custom applications and the default value was chosen instead.
## PAN-142604
Fixed an issue where virtual memory of a process (configd) continuously increased until it stopped responding.
## PAN-142548
Fixed an memory leak issue in a process (configd) that caused the firewall to be inaccessible.
## PAN-140669
Fixed a memory leak issue caused by a process (mgmtsrvr).
## PAN-140492
Fixed an issue on the firewall where, with SSL Forward Proxy feature enabled, random file downloads over a decrypted session would stall or hang in the middle.
## PAN-139661
Fixed an issue that led to exhaustion of memory, which resulted in path monitoring failures when Cortex Data Lake was configured.
## PAN-139007
Fixed an issue where **URL Filtering** logs were misaligned when exported from the firewall due to the presence of a comma in the **User-Agent** field of the logs.
## PAN-138573
Fixed an issue where the keyword **[Disabled]** was missing from the disabled policies exported in CSV/PDF format.
## PAN-137741
Fixed an issue where the data for a botnet report was deleted before the botnet report was completed.
## PAN-137375
Fixed an issue where a process (ikmgr) stopped responding during IKE SA negotiations when Online Certificate Status Protocol (OCSP) was enabled.
## PAN-136652
```caveat
PA-3200 Series and PA-800 Series firewalls only
```
Fixed an issue where you were unable to disable auto negotiation on small form-factor pluggable (SFP) ports.
## PAN-136607
Fixed an issue with GTP event packet capture (pcap) where enabling **Packet Capture** did not work.
## PAN-134909
Fixed an issue where region information was not called due to a mismatch in uppercase and lowercase letters in the region name.
## PAN-134840
Fixed an issue where pre-logon users failed authentication if the cookie was expired, instead of using certificate authentication.
## PAN-134467
Fixed an issue with the GlobalProtect portal where pre-logon authentication failed when agent Config Selection Critiera was configured on the firewall.
## PAN-134251
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where unplugging cables from Quad Small Form-factor Pluggable (QSFP) interfaces on 100G NPC causes path monitoring failures.
## PAN-133885
Fixed an issue where DNS proxy failed due to incorrect mapping of the DNS transaction ID.
## PAN-132055
Fixed an issue where a process (mgmtsrvr) was unresponsive when the number of active file descriptors was greater than 1024.
## PAN-129234
Fixed an issue where syslog connection failures were frequently reported in system logs.
## PAN-124681
A fix was made to address a vulnerability where Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls were not cleared before the data frame was created ([CVE-2021-3031](https://security.paloaltonetworks.com/CVE-2021-3031)).
## PAN-121604
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where a process (brdagent) stopped responding during firewall bootup.
## PAN-110720
Fixed an issue where a high volume of traffic over SSL VPN caused a process (all_pktproc) to unexpectedly stop responding.
## PAN-109877
Fixed an issue where BGP flapped continuously with Jumbo Frames enabled on the firewall.
## PAN-100489
Fixed an issue where the **Group found** flag was set to **NO** on User-ID logs on the web interface, even when the user belonged to a group retrieved from the Active Directory (AD) server.
@@ -0,0 +1,289 @@
---
type: Addressed
product: PAN-OS
version: 9.0.13
---
## PAN-163538
Fixed an issue on multi-dataplane platforms where traffic through Large Scale VPN (LSVPN) tunnels dropped with the error message tunnel resolution failure.
## PAN-161121
Fixed an issue on the Panorama management server that caused invalid reference errors when attempting to delete an address object (**Objects > Addresses**) after removing the address object reference from an address group (**Objects > Address Groups**) resulting in you being unable to commit and push the configuration to managed firewalls.
## PAN-160376
Fixed an issue where, for local administrators using an authentication profile, the **save filter** (**Monitor > Logs**) option was grayed out.
## PAN-158650
Fixed an issue where several operations and processes stopped responding due to a deadlock issue between the CLI thread and the Terminal Server (TS) agent message processing the thread.
## PAN-158328
Fixed an issue where the firewall stopped populating the multicast FIB table with OIL entries for multicast groups.
## PAN-157049
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the firewall processed internal path monitoring packets more slowly than expected when processing large amounts of traffic, which caused the dataplane to restart.
## PAN-156375
Fixed an issue where multiple all_pktoproc daemons restarted while processing HTTP/2 traffic in sw_offload.
## PAN-155656
Fixed an issue where multicast RTP traffic triggered unicast RTP Control Protocol (RTCP), and the predict session failed to install, which blocked the parent RTP session from forwarding packets.
## PAN-155517
Fixed an issue where a sudden increase in URL-cloud data challenged the cache capacity of the device.
## PAN-155453
Fixed an issue in the configuration logs where the destination zone was masked by asterisks.
## PAN-155294
Fixed an issue where iPad devices did not display Captive Portal multi-factor authentication (MFA) pages correctly when using Okta for push notifications.
## PAN-154844
Fixed an issue where commits and autocommits repeatedly failed due to an out-of-memory (OOM) condition that disrupted the processes pan_task and devsrvr.
## PAN-154812
Fixed a memory leak issue related to a process (configd) that was caused by log queries filtering by address.
## PAN-154195
Fixed an issue where the firewall dropped VoIP traffic over IPSec with counters flow_predict_convert_rtp_drop and flow_predict_convert_failed.
## PAN-153526
```caveat
PA-7000 Series firewalls with 100G NPC (Network Processing Cards) only
```
Fixed an issue where multicast groups were not set correctly, which caused ARP entries to display as incomplete and not update to correct values.
## PAN-153294
Fixed an issue on the firewall where a GlobalProtect username authenticated via Kerberos was unnecessarily normalized to SAMAccountName format.
## PAN-153261
Fixed an issue where not all fragmented packets were transmitted, which caused increased packet buffer usage.
## PAN-152998
Fixed an issue where the User-ID process CPU usage remained high when a large number of TS agents were configured but only a few were connected.
## PAN-152813
Fixed an issue with configuration memory leaks on Panorama that caused a process (configd) to restart.
## PAN-152743
Fixed an issue where, when initial flows from both directions reached the firewall at the same time, a race condition occurred, which caused the firewall to display the following error message: Duplicate flows detected while inserting <number>;, flow <number> with the same key. The flow keys were identical due to the flows having the same SRC and DST ports.
## PAN-152648
Fixed an issue where multiple all_pktproc processes stopped responding, which caused the dataplane to restart.
## PAN-152253
Fixed an issue where the Destination NAT with **DNS Rewrite** enabled and set to **forward** did not work when the destination IP address was a single IP address instead of an IP range.
## PAN-152103
Fixed a memory leak issue where a process (dnsproxy) did not properly release memory after use.
## PAN-152098
Fixed an issue where the Policy Optimizer for some device groups showed incorrect data with a - character in the rule usage column.
## PAN-151888
Fixed an issue where remote users were able to save log filters, which created a local user with the same username. With this fix, remote users cannot save a log filter.
## PAN-151503
Fixed an intermittent issue where memory was not fully freed after a Panorama commitAll completion on the firewall.
## PAN-151458
Fixed an issue on firewalls with high availability active/active configurations where GlobalProtect gateways timed out on-demand connections. This occurred because the **Inactivity Logout** timer did not reset.
## PAN-150998
Fixed an issue where, when deploying a VM-Series firewall on VMware NSX that had been assigned a serial number that was used by a previously deactivated firewall, the new firewall was deployed in a deactivated or partially deactivated state.
## PAN-150968
Fixed a rare issue with HTTP/2 decryption that caused packet header bytes to be corrupted, which caused packet drops.
## PAN-150867
An enhancement was made to enable additional logging during kernel panic/oops that helps identify the cause.
## PAN-150852
Fixed an issue with SMTP that occurred when attachment file names were longer than the allocated buffer. If the file name was longer than the buffer and Layer 7 inspection was enabled, the file was dropped, which caused session errors and an email to not be sent.
## PAN-150798
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where Network Processing Cards (NPC) took longer than expected or failed to boot.
## PAN-150085
Fixed an issue where a process (configd) stopped responding which caused context switches to slow.
## PAN-150008
Fixed an issue on the firewall where configuring auto-tagging based on URL filtering logs resulted in tags being added to source IP addresses and not matching the log forwarding filter match criteria.
## PAN-149641
Fixed an issue where firewalls stopped refreshing IP tag information when configured with the **VM Information Sources** feature with a VMWare vCenter Server.
## PAN-149339
Fixed an issue where, when an ECMP route changed, the flow table in the offload engine was not updated.
## PAN-149283
Fixed an issue where editing device log forwarding in the collector group then filtering specific firewalls and adding new firewalls caused the old firewalls to disappear from the log forwarding preferences list.
## PAN-148549
Fixed an issue where newly created interface management profiles were unable to be linked to subinterfaces.
## PAN-147959
Fixed an issue where the last commit state did not change to config sent to device when pushing a device group configuration in the **Managed Device > Summary** page on Panorama.
## PAN-147254
jQuery was updated to 3.5.1.
## PAN-147221
Improved QoS scheduling for Bidirectional Forwarding Detection (BFD) and BGP to address the internal handling of BGP and BFD packets under high resource constraints
## PAN-146787
Fixed an issue where traffic incorrectly matched URL based authentication policies.
## PAN-146236
Fixed an issue where the firewall was unable to properly create stream control transmission protocol (SCTP) sessions for multi-homed environments when multiple endpoints on the same SCTP associations sent INIT/INIT-ACK chunks during handshakes.
## PAN-145733
Fixed an issue where the SNMP INDEX for panZoneTable on the PAN-COMMON-MIB.my file did not work as expected, which led to entries in panZoneTable not being uniquely identified.
## PAN-145417
Debug commands were added to address an issue where the firewall connect to Cortex Data Lake due to the Online Certificate Status Protocol (OSCP) message missing the nextUpdate value in the OSCP response.
## PAN-144975
Fixed an intermittent issue where a high traffic load in a Layer 2 deployment caused SNMP and Panorama health monitoring failures.
## PAN-144887
```caveat
Panorama virtual appliances in high availability (HA) configurations with VMware NSX plugin only
```
Fixed an issue where dynamic address group updates and configuration pushes failed when new plugins were installed or uninstalled, or when a process (configd) was restarted or reinitialized.
## PAN-144538
Fixed an issue where locally disabling the rule hit-count feature on Panorama caused a memory leak.
## PAN-143485
Fixed a memory leak issue related to a process (devsrvr).
## PAN-143332
Fixed an issue where deploying the Master Key to managed devices through Panorama using the **Deploy Master Key** feature (**Panorama > Managed Devices > Summary > Deploy Master Key**) failed.
## PAN-141255
Removed the fields **device SN** and **device name** on Panorama from the predefined filter used in **Log Forwarding** and **Log Settings**.
## PAN-140222
Fixed an issue where logs were not forwarded to the syslog server with the following error message: profile: Syslog (1) is duplicated.
## PAN-137233
Fixed an issue where authenticating to GlobalProtect via expired SAML requests (waiting more than 10 minutes) still sent authentication to the SAML server. This invalidated the previously connected gateway and connected users to the second best gateway.
## PAN-136073
Fixed an issue where the High Speed Chassis Interconnect (HSCI) port flapped continuously after an upgrade or reboot.
## PAN-134799
Fixed an issue where packets of the same session were forwarded through a different member of an Aggregate Ethernet (AE) group once the session was offloaded.
## PAN-134461
Fixed an issue where an admin user authenticated to Panorama with RADIUS and assigned a Device Group and Template Admin role using access domains was unable to add a managed firewall to Panorama and received the following error message: Import failed user <username> does not exist.
## PAN-131474
A fix was made to address a vulnerability related to information exposure through log files in PAN-OS where the connection details for a scheduled configuration export were logged in system logs ([CVE-2021-3037](https://security.paloaltonetworks.com/CVE-2021-3037)).
## PAN-129927
```caveat
VM-Series firewalls only
```
Fixed an issue where firewalls with Layer 3 subinterfaces reset Class of Service (CoS) bits in 802.1q.
## PAN-126815
Fixed an issue where the GlobalProtect gateway and portal failed to generate authentication cookies for pre-logon and user-logon events due to a failure to populate the remote_addr field in the authentication cookie.
## PAN-124579
Fixed an issue where a process (all_task_3) restarted, which caused the tunnels to reset.
## PAN-123638
Fixed an issue where DHCP was not configurable from Panorama templates in single virtual system (vsys) mode.
## PAN-123041
Fixed an issue where commits failed due to OOM events caused by the PAN-DB database.
## PAN-120013
Fixed an issue where secure communication settings were incorrectly synchronized between Panorama appliances in an HA configuration.
## PAN-119161
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where firewalls were unable to start up an NPC due to a process (brdagent) restarting repeatedly.
## PAN-79640
Fixed an issue where the firewall intermittently logged incorrect actions for WildFire submissions and reports.
@@ -0,0 +1,13 @@
---
type: Addressed
product: PAN-OS
version: 9.0.14-h4
---
## BLANK-000000
Fixed a Denial-of-Service (DoS) vulnerability in the GlobalProtect portal and gateway ([CVE-2021-3063](https://security.paloaltonetworks.com/CVE-2021-3063)).
## PAN-171203
Fixed an issue in a high availability configuration where, when one firewall was active and its peer was in a suspended state, the suspended firewall continued to send traffic, which triggered the detection of duplicate MAC addresses.
@@ -0,0 +1,336 @@
---
type: Addressed
product: PAN-OS
version: 9.0.14
---
## WF500-5568
Fixed an issue where a firewall in FIPS mode running PAN-OS 8.1.18 or a later version failed to connect with a WildFire appliance in normal mode.
## WF500-5513
Fixed an issue where cloud queries failed, which generated system logs. The issue occurred because a hash was not found in the cloud.
## PAN-170740
Fixed an issue with the google-docs-uploading application that occurred if a Security policy rule was applied to a Security profile and traffic was decrypted.
## PAN-168921
Fixed an issue in active/active high availability (HA) configurations where traffic with complete packets was showing up as incomplete and being disconnected due to a non-session owner device closing the session prematurely.
## PAN-168298
Fixed an issue where a firewall superuser using an LDAP authentication profile that was pushed from Panorama was unable to save the filter under **Monitor > Logs**.
## PAN-167989
Fixed a timing issue between downloading and installing threads that occurred when Panorama pushed content updates and the firewall fetched content updates simultaneously.
## PAN-166836
Fixed an issue where session failed due to resource unavailability.
## PAN-166328
```caveat
PA-7000 Series firewalls with NPCs only
```
Fixed an issue where path monitoring failure occurred while hot inserting a 100G NPC (network processing card) into the firewall.
## PAN-166296
Fixed an issue where an unavailable certificate revocation list (CRL) from the server side caused an infinite loop on a process (sslmgr), which resulted in it not responding for other tasks.
## PAN-166241
A fix was made to address an improper restriction of XML external identity (XXE) reference in the PAN-OS web interface that enabled an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that caused the service to crash ([CVE-2021-3055](https://security.paloaltonetworks.com/CVE-2021-3055)).
## PAN-165661
Fixed an issue in an HA active/active configuration where an administrative shutdown message was not sent to the BGP peer when the firewall went into a suspended state, which delayed convergence.
## PAN-164922
Fixed an issue on Panorama where a context switch to a managed firewall running PAN-OS 8.1.0 to PAN-OS 8.1.19 failed.
To utilize this fix, upgrade Panorama to PAN-OS 10.0.5.
## PAN-164846
Fixed an issue where packet buffers were depleted.
## PAN-164646
Fixed an issue where tunnel monitoring in the Large Scale VPN (LSVPN) displayed as down in both the CLI and the web interface due to incorrect dataplane ownership.
## PAN-164422
```caveat
VM-Series firewalls only
```
A fix was made to address improper access control that enabled an attacker with authenticated access to GlobalProtect portals and GlobalProtect gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon Web Services (AWS) ([CVE-2021-3062](https://security.paloaltonetworks.com/CVE-2021-3062)).
## PAN-164056
Fixed a memory issue for LSVPNs with multiple dataplane systems.
## PAN-162710
Debug code was introduced to enable additional logging for flow lookup.
## PAN-162600
Fixed an issue where, when the GlobalProtect client sent UDP/4501 traffic that was destined for the GlobalProtect gateway inside the GlobalProtect tunnel, the firewall still processed the traffic, which caused routing loops.
## PAN-161260
Fixed a memory leak issue related to a process (useridd) that occurred when processing high amount of HIP reports as well as a memory leak issue related to the sslvpn process that occurred when the firewall was configured as a GlobalProtect satellite.
## PAN-160744
Fixed an issue where the negative time difference between the dataplane and the management plane during the client certificate info check prevented the GlobalProtect client from connecting to the GlobalProtect gateway with the following error message: Required client certificate not found.
## PAN-160455
A fix was made to address an issue where certain invalid URL entries contained in an External Dynamic List (EDL) caused the devsrvr process to stop responding ([CVE-2021-3048](https://security.paloaltonetworks.com/CVE-2021-3048)).
## PAN-159944
Fixed an issue where a process (dnsproxyd) stopped responding due to an error in the DNS cache operation.
## PAN-159826
Fixed an issue where SSL VPN memory leaked when the default browser for SAML authentication on GlobalProtect was not enabled.
## PAN-159295
Fixed an issue where scheduled configuration export files saved in the /tmp folder in root were not periodically purged, which caused the root partition to fill up.
## PAN-159135
Fixed an issue where the firewall rejected SAML Assertions, which caused user authentication failure when the **Validate Identity Provider Certificate** was enabled in the SAML Server Profile in vsys3 or above.
## PAN-158988
Fixed an issue with HTTP Header Insertion where the payload was truncated when processing a segmented TCP stream and when the client retransmitted the packet with the same sequence number that was previously received segmented.
## PAN-158844
Adds additional debugging to be used in identifying the malformed references causing process crashes during FQDN refresh.
## PAN-158774
Fixed an issue where random DNS queries dropped with the counter ctd_dns_wait_pkt_drop when DNS security was enabled.
## PAN-158723
A fix was made to address an improper handling of exception conditions in the PAN-OS dataplane that enabled an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that caused the service to crash ([CVE-2021-3053](https://security.paloaltonetworks.com/CVE-2021-3053)).
## PAN-158638
Fixed an issue where the firewall returned the following error message when attempting to request a device certificate using a one-time password (OTP): invalid ocsp response sig-alg.
## PAN-158439
Fixed a memory leak on the management server process on Firewall.
## PAN-158262
A buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS software allows remote attackers to execute arbitrary code.
A fix was made to address a buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS that allowed a remote attacker to execute arbitrary code ([CVE-2020-10188](https://security.paloaltonetworks.com/CVE-2020-10188)).
## PAN-157834
Fixed an issue with missing zone entries in CSV or PDF export files.
## PAN-157721
Fixed an issue where the firewall dropped GPRS tunneling protocol (GTPv2) Create Session Requests and Responses that had IEs 201 and 202 with the error Abnormal GTPv2-C message with invalid IE.
## PAN-157346
Fixed an issue where HIP custom checks for plist failed when the HIP exclusion category were configured under (**Mobile User Template > Network > GlobalProtect > Portal<portal-config> > Agent<agent-config> > HIP Data Collection**).
## PAN-157035
```caveat
PA-5200 Series firewalls only
```
Fixed an intermittent issue where multicast packets traversing the firewall in VLAN configurations experienced higher drop rates than expected.
## PAN-157027
Fixed an issue where, when stateless GTP-U traffic hit a multi-dataplane firewall, an inter-dataplane fragmentation loop occurred, which caused high dataplane resource usage.
## PAN-156482
Fixed a packet buffer issue where HTTP2 packets were held for category lookup and the HTTP request was across multiple packets.
## PAN-156240
A fix was made to address an issue where a cryptographically weak pseudo-random number (PRNG) was used during authentication to the PAN-OS interface. As a result, attackers with the capability to observe their own authentication secrets over a long duration on the firewall had the ability to impersonate another authenticated web interface administrators session ([CVE-2021-3047](https://security.paloaltonetworks.com/CVE-2021-3047)).
## PAN-156225
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the HA1-B port remained down after an upgrade from PAN-OS 9.1.4 to later 9.1 releases and from PAN-OS 10.0.0 to PAN-OS 10.0.4.
## PAN-155049
Fixed an issue with SSLVPN memory leaks related to the GlobalProtect portal **Config Selection Criteria**.
## PAN-154602
Fixed an issue where GlobalProtect users got disconnected after modifying floating IP HA configuration.
## PAN-154557
Fixed an issue that caused a process (useridd) core dump when parsing the Subject Alternative Name from a client certificate sent in the HIP report.
## PAN-154403
Fixed an issue with HIP matching logic for missing patches where previous behavior indicated missing patches when no patches were missing.
## PAN-154376
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
## PAN-154016
Fixed an issue where auto-commits failed for VM-Series firewalls bootstrapped with new content installation during bootstrap. The firewalls displayed the following error message: Details:Error: Undefined application <application-name>.
## PAN-153814
Fixed an issue where the firewall displayed the URL Filtering Safe Search Block Page on the specific site only, even when the traffic was matched to a specific rule that did not have any URL filtering policies.
## PAN-153382
Fixed an issue where the per-minute resource monitor was three minutes behind.
## PAN-153316
CLI commands were added to address an issue where virtual memory on a process (configd) exceeded the new 32G limit.
- To disable the virtual memory limit, use debug software disable-virt-limit.
- To enable the virtual memory limit, use debug software enable-virt-limit.
## PAN-153213
Fixed a rare issue where TCP packets randomly dropped due to reassembly failure.
## PAN-152497
Fixed an issue where the firewall was unable to create a new GTP-U session when it received Create Session Response messages, which caused the following error message to display in the GTP log: GTPv1 message failed stateful inspection.
## PAN-152458
```caveat
VM-Series firewalls on Microsoft Hyper-V only
```
Fixed an issue where, when upgrading to PAN-OS 9.0.8 or later, ethernet packets dropped after adding VLAN tags during egress from a subinterface. To leverage this fix, set the interface level maximum transmission unit (MTU) to 1496 or less.
## PAN-151521
Fixed an issue where a process (logrcvr) continuously restarted at pan_hash_iter_next_i.
## PAN-151395
Fixed an issue where the firewall repeatedly logged connection failures to a configured Log Collector.
## PAN-150534
Fixed an issue where authentication logs with the subtype SAML were not forwarded to the syslog server.
## PAN-150467
Fixed a memory leak issue with a unified query that caused a process (mprelay) to restart due to an out-of-memory (OOM) condition.
## PAN-150337
A fix was made to address a reflect cross-site scripting (XSS) vulnerability in the PAN-OS web interface that enabled an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performed arbitrary actions in the web interface as the targeted authenticated administrator ([CVE-2021-3052](https://security.paloaltonetworks.com/CVE-2021-3052)).
## PAN-150110
Fixed an issue where Elasticsearch restarted unexpectedly when it ran out of memory. This was due to the vm.max-map-count value being set incorrectly in the newer version of Elasticsearch (starting from PAN-OS 9.0). With this fix, the value is set correctly.
## PAN-150023
A fix was made to address an issue where an improper authentication vulnerability enabled a Security Assertion Markup Language (SAML) authenticated user to impersonate any user in the GlobalProtect portal and GlobalProtect gateway when they were configured to use SAML authentication ([CVE-2021-3046](https://security.paloaltonetworks.com/CVE-2021-3046)).
## PAN-149501
A fix was made to address a memory corruption vulnerability in the GlobalProtect Clientless VPN that enabled an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication ([CVE-2021-3056](https://security.paloaltonetworks.com/CVE-2021-3056)).
## PAN-147827
Fixed an issue where, when SIP traffic traversing the firewall was sent with a high QoS Differentiated Services Code Point (DSCP) value, the DSCP value was reset to the default setting (CS0).
## PAN-147783
Checks were added to help prevent the dataplane from restarting.
## PAN-147781
A fix was made to address an issue where an OS command argument injection vulnerability in the PAN-OS web interface enabled an authenticated administrator to read any arbitrary file from the file system ([CVE-2021-3045](https://security.paloaltonetworks.com/CVE-2021-3045)).
## PAN-146250
Fixed an issue where, in two separate but simultaneous sessions, the same software packet buffer was owned and processed.
## PAN-146107
Fixed an issue where memory allocation failure caused a process (pan_comm) to restart several times, which caused the firewall to restart.
## PAN-144470
Fixed an issue where driver descriptor rings were out of sync in the control plane to dataplane direction, which caused internal path monitoring heartbeat failures.
## PAN-142621
Fixed an issue where the firewall was unable to log debug information in case of kernel panic.
## PAN-141813
Fixed an issue where multiple daemons restarted due to a management plane ARP overflow.
## PAN-138727
A fix was made to address a time-of-check to time-of-use (TOCTOU) race condition in the PAN-OS web interface that enabled an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges ([CVE-2021-3054](https://security.paloaltonetworks.com/CVE-2021-3054)).
## PAN-137147
Fixed an issue where configuration commits failed due to the dataplane running out of memory in policy cache allocation.
## PAN-136347
Fixed an issue where DNS proxy TCP connections were processed incorrectly, which caused a process (dnsproxy) to stop responding.
## PAN-133886
Fixed an issue where GlobalProtect users were unable to connect to mobile gateways when download of a large CRL failed due to timeouts that resulted in CRL check failures.
## PAN-132035
Fixed an issue on Panorama appliances in an active/passive HA configuration where a managed firewall generated high priority alerts that it failed to connect to the passive Panorama appliance's User-ID agent server. This issue occurred because the firewall was only able to connect to one Panorama User-ID server at a time, and it connected only to the active Panorama appliance's User-ID server.
## PAN-115553
```caveat
PA-5200 Series firewalls only
```
Fixed an intermittent issue where internal path monitoring failed, which caused the firewall to unexpectedly restart.
## PAN-110429
Fixed an issue with firewalls in an HA configuration where multiple all_pktproc processes stopped responding due to missing heartbeats, which caused service outages.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 9.0.16-h2
---
## PAN-190175
A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)).
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 9.0.16-h3
---
## PAN-192999
A fix was made to address [CVE-2022-0028](https://security.paloaltonetworks.com/CVE-2022-0028).
@@ -0,0 +1,13 @@
---
type: Addressed
product: PAN-OS
version: 9.0.16-h6
---
## PAN-237871
```caveat
WF-500 appliances and PAN-DB private cloud deployments only
```
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
@@ -0,0 +1,13 @@
---
type: Addressed
product: PAN-OS
version: 9.0.16-h7
---
## PAN-237876
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,17 @@
---
type: Addressed
product: PAN-OS
version: 9.0.17-h1
---
## PAN-159364
A fix was made to address customer and internal bugs.
## PAN-152022
A fix was made to address customer and internal bugs.
## PAN-136676
A fix was made to address customer and internal bugs.
@@ -0,0 +1,21 @@
---
type: Addressed
product: PAN-OS
version: 9.0.17-h5
---
## PAN-239241
Extended the root certificate for WildFire appliances to December 31, 2032.
## PAN-237935
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
## PAN-237876
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,37 @@
---
type: Addressed
product: PAN-OS
version: 9.0.17
---
## PAN-189414
Fixed an issue where TCP packets were dropped during the first zone transfer when DNS security was enabled.
## PAN-188303
Fixed an issue where the serial number displayed as unknown after running the show system state CLI command.
## PAN-180916
Fixed an issue where DNS security caused the (time-to-live) value of the pointer record (PTR) to be overwritten with a value of 30 seconds.
## PAN-176153
```caveat
PA-7000 Series firewalls with 20G NPC (Network Processing Cards) only
```
Fixed a memory allocation issue where the NPC was unable to successfully boot up on the firewall.
## PAN-175003
Fixed a connection issue with the sysd process that caused FIB entries to not be updated.
## PAN-149008
Fixed an issue where the CLI command Show config running following the CLI command set cli op-command-xml-output on produces an unreadable output.
## PAN-127479
A fix was made to address [CVE-2022-0022](https://security.paloaltonetworks.com/CVE-2022-0022).
@@ -0,0 +1,177 @@
---
type: Addressed
product: PAN-OS
version: 9.0.1
---
## PAN-113911
Fixed an issue on PA-5200 Series firewalls where the dataplane stopped responding due to a deadlock when you accessed the stream session table.
## PAN-113845
Fixed an issue where content installation failed and displayed the following error message: Error: failed to handle TDB_UPDATE_BLOCK, after you upgraded to PAN-OS® 9.0.
## PAN-113771
A security-related fix was made to allow Online Certificate Status Protocol (OCSP) checks while disallowing HTTP calls.
## PAN-113682
Fixed an issue where the dataplane restarted when processing HTTP/2 traffic with padded DATA frames.
## PAN-113675
A security-related fix was made to address an authentication bypass vulnerability in PAN-OS Management Web Interface (CVE-2019-1572/PAN-SA-2019-0005).
## PAN-113512
Fixed an issue where an XML API response for an external dynamic list did not return invalid or ignored members after you upgraded to PAN-OS 9.0.
## PAN-113446
Fixed an issue where the firewall unintentionally generated the following system log: Installed content package WildFire is newer than available package, skipping, when you checked for WildFire® updates.
## PAN-113302
Fixed an issue where commits to the Panorama™ configuration after you upgraded to PAN-OS 9.0 failed with the following error message: statistics-service is invalid.
## PAN-112700
```caveat
PA-7000 Series firewalls in an HA configuration only
```
Fixed an issue that occurred after you upgraded to PAN-OS 9.0 where some logs displayed a different rule name than the rule name associated with the universally unique identifier (UUID).
## PAN-112592
Fixed an issue on a firewall where the system log did not generate an alert for AutoFocus™ license expiry.
## PAN-112458
Fixed an issue on a firewall where the management server stopped responding when debugs were configured and you exported traffic logs (**Monitor** > **Traffic <traffic-name>** > **Export to CSV**).
## PAN-112428
Fixed an intermittent issue where autocommits failed and Panorama stopped displaying device groups when managing a WildFire appliance that was running an earlier maintenance release of the same feature release (such as using Panorama running PAN-OS 8.1.6 to manage a WF-500 appliance that was running PAN-OS 8.1.3).
## PAN-112305
Fixed an issue where source (**Object** > **Dynamic Lists <list-name>** > **Create List**) URLs, which contained double escape characters caused external dynamic list entries to display incorrect values in the policies.
## PAN-112274
Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) stopped responding when a role-based user with privacy settings disabled, viewed a scheduled report that required data anonymization.
## PAN-112098
Fixed an intermittent issue on a firewall where outbound traffic failed with an error message: (proxy decrypt failure) when configured with HTTP Header Insertion (**Objects** > **Security Profiles** > **URL Filtering <filter-name>** > **HTTP Header Insertion**).
## PAN-111897
Fixed an issue where the tags were not set on OSPFv3 routes redistributed to BGP-3.
## PAN-111850
Fixed an issue where the firewall did not capture the number of packets in the threat packet capture (pcap) as configured in the extended packet capture length setting.
## PAN-111822
```caveat
PA-3200, PA-5200, and PA-7000 Series firewalls only
```
Fixed an intermittent issue on a firewall configured with policy-based forwarding (PBF) and symmetric return, where traffic dropped because the ARP table did not get updated.
## PAN-111638
Fixed an issue where the external dynamic list did not update after a scheduled refresh of the list.
## PAN-111061
A fix was made to upgrade OpenSSH software included with PAN-OS ([PAN-SA-2020-0005](https://security.paloaltonetworks.com/PAN-SA-2020-0005) / CVE-2016-10012).
## PAN-111052
Fixed an issue where a firewall silently dropped TCP packets when you enabled the Antivirus profile while the software deterministic finite automation (DFA) option is disabled (DFA is disabled by default).
## PAN-110441
```caveat
PA-5200 Series firewall only
```
Fixed an intermittent issue where the internal path monitoring failed, which caused the firewall to unexpectedly restart.
## PAN-110341
Fixed an issue where the firewall sent RIP updates more frequently than expected.
## PAN-110336
```caveat
PA-3000, PA-3200, PA-5000, PA-5200, and PA-7000 Series firewalls only
```
Fixed an issue where a process (mpreplay) restarted and caused the offload traffic to drop.
## PAN-108620
Fixed an issue where Traps ESM logs were sent to the Log Collector but did not display in the web interface (**Monitor** > **Traps ESM**).
## PAN-108575
Fixed an issue where a process (configd) stopped responding and displayed the following error message: configd is down.
## PAN-108409
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where scheduled dynamic updates pushed from Panorama to the managed firewalls failed.
## PAN-108113
Fixed an issue where Bidirectional Forwarding Detection (BFD) did not function on a static route for which the next hop for that route was an FQDN (instead of an IP address).
## PAN-108111
Fixed an issue where Bidirectional Forwarding Detection (BFD) did not function on a BGP peer that was identified using an FQDN (instead of an IP address).
## PAN-107677
Fixed an issue on GlobalProtect™ where Security Assertion Markup Language (SAML) authentication failed when you used a macOS operating system.
## PAN-107006
Fixed an issue where you were unable to search for service objects by destination port numbers.
## PAN-106963
Fixed an issue where the firewall did not display the full URL information in the URL Filtering log (**Monitor** > **URL Filtering**) after a ( '\r' ) return character.
## PAN-106249
```caveat
PA-200, PA-220, and PA-800 Series firewalls only
```
Fixed an issue where the Block IP List option, which is not supported, displayed in the administrator role profile (**Device** > **Admin Role** > **Web UI**).
## PAN-104263
Fixed an issue where the RTC battery reading exceeded the maximum threshold value.
## PAN-103023
Fixed an intermittent issue where a job type (content) caused a firewall configuration failure and the firewall to stop responding.
## PAN-96827
Fixed an issue where BGP command output formats did not display consistently across different PAN-OS releases.
## PAN-92155
Fixed an issue where administrators were unable to configure an IP address using templates for HA2 (**Device** > **High Availability** > **Data Link (HA2)**) after setting the configuration to **IP** or **Ethernet** for Panorama management servers in HA configuration.
## PAN-85691
Fixed an issue where Authentication policy rules that were based on multi-factor authentication (MFA) didn't block connections to an MFA vendor when the MFA server profile specified a Certificate Profile that had the wrong certificate authority (CA) certificate.
@@ -0,0 +1,191 @@
---
type: Addressed
product: PAN-OS
version: 9.0.2
---
## WF500-5023
Fixed an issue on WF-500 appliances where the cluster service took longer than expected to start due to a large number of queued sample data.
## WF500-5022
Fixed an issue where a non-functioning CLI command was removed from WF-500 appliances.
## WF500-4974
Fixed an issue on a WF-500 appliance where the static analysis results displayed in the PDF report but did not display in the WildFire® analysis summary of the web interface.
## WF500-4844
Fixed an issue on WildFire appliance clusters where the passive-controller responded with the incorrect Common Name (CN) in the certificate, which caused the registration to fail.
## WF500-4838
Fixed an intermittent issue on a WF-500 appliance where WildFire reports took longer than expected to generate, which caused the task to automatically timeout.
## WF500-4784
Fixed an issue on a WF-500 appliance where during a reboot, the following error message displayed: FATAL: module nbd not found.
## WF500-4743
Fixed an intermittent issue on a WF-500 appliance where the CLI command debug wildfire reset global-database fix became unresponsive.
## PAN-118065
```caveat
M-Series Panorama™ management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the show interface all command in the CLI after you commit.
**Workaround:**Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116919
```caveat
Microsoft Azure only
```
Fixed an issue where the firewall dropped packets passing through IPSec tunnels if you enabled jumbo frames (**Device** > **Setup** > **Session** > **Session Settings**).
## PAN-116658
Fixed a rare issue where the firewall sent HTTP/2 DATA frames with incorrect padding byte lengths, which caused software buffer corruption and a process (all_pktproc) to stop responding.
## PAN-116316
Fixed an issue where RTP and RTCP predict sessions failed, which caused the firewall to stop processing RTSP-based video streaming.
## PAN-116084
Fixed an issue where a VM-Series firewall on Microsoft Azure deployed using MMAP dropped traffic when the firewall was experiencing heavy traffic.
## PAN-115592
Fixed an issue where the firewall rebooted due to a plugin memory leak.
## PAN-115591
Fixed an issue where the snmpd process was leaking memory when polling for global counters.
## PAN-114984
Fixed OpenSSL vulnerability CVE-2019-1559, see [PAN-SA-2019-0039](https://securityadvisories.paloaltonetworks.com/Home/Detail/202) for details.
## PAN-114893
Fixed an issue where a context switch from Panorama to a firewall did not respond as expected when a web browser was used.
## PAN-114804
Fixed an issue where a configuration change resets to "default" when you conducted a search in the Categories (**Objects** > **URL Filtering** > **Categories**) web interface.
## PAN-114601
Fixed an issue where the Allow List (**Device** > **Setup** > **Authentication Setting** > **<authentication profile - name>** > **Authentication**) did not update after you added new users to a group in the Active Directory.
## PAN-114255
Fixed an issue where Bidirectional Forwarding Detection (BFD) went down temporarily during a commit or EDL refresh if you configured a large value for the BFD Hold Time.
## PAN-114003
Fixed an issue on a Panorama management server running PAN-OS 9.0 where a context switch to firewalls did not respond.
## PAN-113829
Fixed an issue where, after you upgraded the firewall to PAN-OS® 9.0, a firewall configured from "none" to "allow" in the custom URL category reverted to "none" after a commit.
## PAN-113692
Fixed an intermittent issue on a firewall in a high availability (HA) active/passive configuration where five minutes after a failover test IP routes disappeared, which caused traffic interruptions.
## PAN-113608
Fixed an issue on a firewall with packet capture (pcap) enabled where the log receiver stopped responding when larger than expected packets were received.
## PAN-113414
Fixed an issue where the User-ID™ (useridd) process stopped responding.
## PAN-112815
Fixed an issue on a firewall in an HA active/passive configuration where a process (useridd) did not respond to the alternate user attribute (**Device** > **User Identification** > **Group Mapping Settings** > **<group mapping-name>** > **User and Group Attributes**) on the passive firewall during a restart.
## PAN-112814
Fixed an issue where H.323-based calls lost audio because the predicted H.245 session was not converted to Active status, which caused the firewall to drop the H.245 traffic.
## PAN-112729
Fixed an issue on Panorama M-Series and virtual appliances where Decrypted Sessions Info (**Panorama** > **Managed Devices** > **Health** > **All Devices** > **<device-name>** > **Sessions**) did not display as expected for VM-Series firewalls.
## PAN-112699
```caveat
VM-Series firewall on AWS running on a C5 or M5 instance only
```
Fixed an issue where you were unable use the mgmt-interface-swap command to [swap the interfaces](https://docs.paloaltonetworks.com/vm-series/9-0/vm-series-deployment/set-up-the-vm-series-firewall-on-aws/about-the-vm-series-firewall-on-aws/management-interface-mapping-for-use-with-amazon-elb.html) for deploying a VM-Series firewall behind a web load balancer (such as AWS ALB or Classic ELB).
## PAN-112626
Fixed an issue where a new DNS Security subscription was not available on your VM-Series firewall after you upgraded to a PAN-OS 9.0® release with a PAYG Bundle 2 license.
## PAN-112445
Fixed an issue on a firewall in an HA active/passive configuration where a race condition caused the firewall to stop responding after an HA1 link flap.
## PAN-112340
Fixed an issue with performance, including high CPU usage, that occurred when you enabled URL Filtering without enabling Threat Prevention in an environment that processes a large number (thousands) of URL look-ups per second per dataplane.
## PAN-112194
Fixed an issue where packet buffers did not release GlobalProtect™ clientless VPN packets, which caused the firewall to stop responding.
## PAN-111679
Fixed an issue where URL filtering profiles were being incorrectly applied to security policies during a commit.
## PAN-111553
Fixed an issue on the Panorama management server where the **Include Device and Network Templates** setting (**Commit** > **Push to Devices** > **Edit Selections** or **Commit** > **Commit and Push** > **Edit Selections**) was disabled by default and caused your push attempts to fail. With this fix, your push will **Include Device and Network Templates** by default.
## PAN-111540
Fixed an issue on PA-5200 Series firewalls where the dataplane stopped responding when the session table was full.
## PAN-111251
Fixed an issue where administrators were unable to use the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule (they were able to execute the command but the firewall did not implement the change).
## PAN-110390
Fixed an issue on PA-7000 Series firewalls where invalid filters caused the device management server to stop responding when you generated a database (DB) report from a remote firewall.
## PAN-110273
Fixed an issue where you were unable to establish OSPF neighborship when an OSPF routing protocol was configured with MD5 authentication and one of the firewalls was restarted.
## PAN-109672
Fixed an issue on a VM-Series firewall in an HA active/passive configuration where the passive firewall received buffered packets while in an idle state when the data plane development kit (DPDK) is enabled.
## PAN-109344
Fixed an issue where service objects did not import into Panorama when you configured them identically but with different names.
## PAN-108374
Fixed an issue on GlobalProtect where you were unable to authenticate when the domain name included the ampersand ( "&" ) character.
## PAN-106518
Fixed an issue on Panorama M-Series and virtual appliances where predefined DHCP options did not accept template variables when you configured a DHCP server for a template.
## PAN-101341
Fixed an issue where administrators configured with Device Group and Template Admin type were unable to perform a global search and returned the following message: Unauthorized request.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 9.0.3-h2
---
## PAN-120745
An enhancement was made to the IP Options field in the TCP/IP header for zone protection profiles.
@@ -0,0 +1,505 @@
---
type: Addressed
product: PAN-OS
version: 9.0.4
---
## BLANK-000000
```caveat
Microsoft Azure only
```
Updates to support changes in Azure Accelerated Networking (AN).
## WF500-4785
Fixed a rare issue on WF-500 appliances where the firewall did not respond after you upgraded the appliance from a PAN-OS® 8.0.1 release to a PAN-OS 8.0.10 or later release. With this fix, you can run the new debug software raid fixup auto CLI command to recover the RAID controller.
## PAN-124658
Fixed an issue where the timer system call activated more frequently than expected, which caused higher than expected CPU usage.
## PAN-123371
Fixed an issue where the Wildfire® Analysis Report incorrectly displayed the following error message: You are not authorized to access this page on the web interface.
## PAN-123079
Fixed an intermittent issue where after a configuration change, a commit caused the dataplane to stop responding.
## PAN-122804
Fixed an issue on Panorama™ M-Series and virtual appliances where the firewall stopped forwarding logs to Cortex™ Data Lake after you upgraded the cloud services plugin to 1.4.
## PAN-122489
```caveat
Microsoft Azure only
```
Fixed an issue where VM-Series firewalls incorrectly renamed (to eth) interfaces connected to Mellanox appliances when **Accelerated networking** was enabled on the firewall.
## PAN-122004
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where the Quad Small Form-factor Pluggable (QSFP) 28 ports 21 and 22 did not respond when plugged in with a Finisar 100G AOC cable.
## PAN-121449
Fixed an issue where **Remove Config** (**Panorama** > **Plugins**) did not remove the configuration for any plugins you have set up on Panorama.
## PAN-121185
Fixed an intermittent issue where domains were not normalized, which caused an incorrect verdict response.
## PAN-120662
```caveat
PA-7000 Series firewalls using PA-7000-20G-NPC cards only
```
Fixed an intermittent issue where an out-of-memory (OOM) condition caused the dataplane or internal path monitoring to stop responding.
## PAN-120548
Fixed an issue where the Captive Portal request limit was ignored when you configured the Captive Portal authentication method to browser-challenge.
## PAN-120409
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where firewalls running a 20G Network Processing Card (NPC) or a 20GQ NPC dropped stream control transmission protocol (SCTP) connections due to incorrect session handling.
## PAN-120342
Fixed an intermittent issue where the dataplane stopped responding when processing a UDP packet that passed through an IPSec tunnel.
## PAN-120194
```caveat
Virtual and M-Series Panorama appliances and Log Collectors only
```
Fixed an issue where closed Elasticsearch (ES) indices were continuing to receive and re-queue logs, which resulted in high CPU usage.
## PAN-119257
Fixed an issue where the firewall could not establish an IKEv2 connection with SHA256 certificates.
## PAN-119187
```caveat
Panorama only
```
Fixed an issue where a file lock was released before the lock was taken, which triggered an erroneous maximum connection timeout that prevented administrators from logging in to and executing commands from the command-line interface (CLI).
## PAN-119030
Fixed an issue on Panorama M-Series and virtual appliances where bootstrapped managed firewalls were disconnected after you performed a partial revert if you did not first perform a manual commit. With this fix, the manual commit is not required.
## PAN-118964
Fixed an issue on VM-Series firewalls where single root I/O virtualization (SR-IOV) did not support packet mmap in access mode and DPDK mode.
## PAN-118784
Fixed an intermittent issue where the firewall dropped a message: Update PDP Context Response and did not update the General Packet Radio Service (GPRS) Tunneling Protocol for User Data (GTP-U).
## PAN-118509
Fixed an issue on Panorama M-Series and virtual appliances where shared policies were out of sync due to an empty stream control transmission protocol (SCTP) after you upgraded the firewall from PAN-OS 8.0.16 to PAN-OS 8.1.8.
## PAN-118423
Fixed an intermittent issue with local high availability (HA) status changes where a process (mprelay) failed to commit changes to the HA state.
## PAN-118411
Fixed an issue where ARP entries took longer than expected to age out in a single run.
## PAN-118407
Fixed an issue where an internal path monitoring failure due to a buffer leak caused the firewall to reboot.
## PAN-117923
Fixed an issue where the management server stopped responding when an incorrect filter was used to filter traffic logs instead of displaying an error message.
## PAN-117921
Fixed an issue where you were unable to create GTP inner sessions, which caused the firewall to drop GTP-U data packets when the firewall was deployed on S1-U and S-11 interfaces.
## PAN-117916
Fixed an issue where the dataplane stopped responding when you pushed permitted IP addresses from Panorama to managed firewalls.
## PAN-117720
```caveat
GlobalProtect™ Clientless VPN environments only
```
Fixed an issue where a process (all_pktproc) stopped responding and caused the firewall to restart unexpectedly when processing GlobalProtect Clientless VPN traffic. To leverage this fix, you must first upgrade (**Devices** > **Dynamic Updates**) to GlobalProtect Clientless VPN content release 79 or a later release.
## PAN-116807
```caveat
PA-7000, PA-5200, and PA-3200 Series firewalls only
```
Fixed an issue where the firewall dropped ICMP error messages when the security policy was configured to allow ICMP.
## PAN-116798
Fixed an issue on Panorama M-Series and virtual appliances where the progress bar for a commit all job incorrectly remained at 0% after a job was completed.
## PAN-116769
Fixed an issue where a process (pan_comm) stopped responding due to a memory allocation error.
## PAN-116729
Fixed an issue where you were unable to deploy bootstrapped content in offline environments due to content validity checks.
## PAN-116634
Fixed an issue where the date in the GlobalProtect HTTP header was incorrectly set to a random date instead of a zero (0), which negatively and falsely impacted security scorecard ratings.
## PAN-116613
Fixed an issue on a VM-Series firewall deployed in Microsoft Azure where packets dropped silently due to a kernel error.
## PAN-116513
Fixed an issue where VM-Series firewalls did not bootstrap successfully when you included the software version in the software folder of the bootstrap package.
## PAN-116436
```caveat
Panorama virtual appliances only
```
Fixed an issue where a disk calculation error resulted in an erroneous opt/panlogs/ partion full condition and caused a process (CDB) to stop responding.
## PAN-116416
Fixed an issue on Panaorama M-Series and virtual appliances where a process (configd) stopped responding when you performed a commit to a large number of firewalls.
## PAN-116383
Fixed an issue with Panorama on Azure where the configuration of an HA pair became out of sync due to different plugin versions being detected even though the same versions were installed on both peers.
## PAN-116280
Fixed an issue where the firewall displayed a static route warning when the next hop IP address was not included in the subnet of the outgoing interface.
## PAN-116227
Fixed an issue on Panorama M-Series and virtual appliances where traffic logs did not display data when the IPv6 address filter is based on netmask.
## PAN-116218
Fixed an issue where the test routing bgp virtual-router default restart peer Peer-v6 CLI command did not execute the operational request and returned the following error message: op command for client routed timed out as client is not available.
## PAN-116128
Fixed an issue where a process (logrcvr) stopped responding when packet captures (pcap) were generated for HTTP2 traffic.
## PAN-116123
Fixed an issue where a process (devsrvr) stopped responding when you performed a commit or a configuration validation when the proxy ID contained 24 or more characters.
## PAN-115856
Fixed an issue where Dynamic IP and Port (DIPP) NAT pools did not release used ports after all sessions were removed.
## PAN-115852
Fixed an issue on VM-Series firewalls on AWS where you could not change maximum transmission unit (MTU) values from the web interface and displayed the following error message: Malformed Request.
## PAN-115794
Fixed an issue where, after you upgraded the firewall from PAN-OS 8.1.5 to PAN-OS 9.0.0, the firewall displayed the following validation error: plugins 'read-only' is not an allowed keyword.
## PAN-115792
Fixed an issue where after a refresh of the external dynamic list values from the previous list were not retained, which caused the list values to display 0.0.0.0 and displayed the following error message: HTTP/1.1 500 Internal Server Error.
## PAN-115748
Fixed an intermittent issue on Panorama M-Series and virtual appliances where a memory issue caused the firewall to reboot.
## PAN-115738
Fixed an issue where data logs were generated but the firewall did not forward the logs to the syslog server.
## PAN-115695
Fixed an intermittent issue where a large number of packets were received before acknowledgments were complete, which depleted descriptor queue entries and resulted in high latency during data transfers even though CPU usage looked normal.
## PAN-115450
Fixed a rare issue where a race condition occurred between daemons during a tunnel re-key, which caused BGP sessions to drop from Large Scale VPN tunnels. To leverage this fix, you must run the debug rasmgr delay-nh-update CLI command.
## PAN-115354
Fixed an issue on Panorama M-Series and virtual appliances where renaming a device group followed by a partial commit did not change the device group hierarchy as expected.
## PAN-115287
Fixed an issue where commits failed and displayed the following error message: Commit job was not queued. All daemons are not available.
## PAN-115219
Fixed an issue on Panorama M-Series and virtual appliances where Global Find caused the web interface to stop responding when you searched for common English words.
## PAN-115186
Fixed an issue where SaaS reports were not generated due to report definitions not getting pushed to the log collector.
## PAN-114958
Fixed an issue where the User-ID™ (useridd) process consumed more CPU cycles than expected when you configured User-ID redistribution.
## PAN-114889
Fixed an issue where a Panorama template push to a firewall with a PAN-OS 8.1 release or earlier resulted in the deletion of split tunnel configurations when any address objects or address groups are included. With this fix, you still must remove all address groups before pushing templates to a PAN-OS 8.1 or earlier release.
## PAN-114867
Fixed an issue where GlobalProtect gateway client configuration generation failed when a matching rule existed.
## PAN-114844
Fixed an issue on Panorama M-Series and virtual appliances where malformed API calls caused the firewall to reboot.
## PAN-114779
Fixed an issue where log purging took longer than expected, which prevented the firewall from capturing traffic logs.
## PAN-114567
Fixed an issue where the Eventid eq globalprotectportal-config-succ system query caused the management server (mgmtsrvr) process to stop responding.
## PAN-114566
Fixed an issue where after a commit the firewall displayed the following error message: No Valid DNS Security License even when the license was valid and successfully applied.
## PAN-114533
Fixed an issue where traffic was blocked by the safe search enforcement instead of the intended allow rule.
## PAN-114526
Fixed an issue where larger than expected number of packets sent over a GTP-U tunnel caused packet captures to fill the files faster than expected. With this fix, you can run the debug dataplane packet-diag set capture gtpu-lvl [1-30] command to ensure GTP-U traffic are captured.
## PAN-114475
Fixed an issue where Panorama in FIPS mode defaulted to FIPS-CC mode instead of Normal mode.
## PAN-114427
Fixed an issue where an empty host name in the HTTP header caused a web server process (websrvr) to stop responding when you accessed the captive portal redirect page.
## PAN-114264
Fixed an issue where sessions were offloaded as the application identification was performed when you configured a custom application with **Continue scanning for other application**.
## PAN-114160
Fixed an issue where you were unable to download ZIP files greater than 3GB through a GlobalProtect Clientless VPN application.
## PAN-114105
Fixed an issue on a Panorama M-Series appliance where the Summary (**Panorama** > **Managed Devices** > **Summary**) web interface refreshes every 10 seconds when set to manually refresh.
## PAN-114090
Fixed an issue on a Panorama virtual appliance in Legacy mode and in an HA active/passive configuration where logs were forwarded only to the active firewall.
## PAN-114002
Fixed an issue where you were unable to import variable CSV files when variable names contained a character space.
## PAN-113971
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where the High Speed Chassis Interconnect (HSCI) link flapped after you rebooted the firewall.
## PAN-113930
Fixed an issue on VM-Series firewalls where CPU loads were uneven across cores when more than 8 cores were allocated to the dataplane.
## PAN-113912
Fixed an issue where a process (ikemgr) stopped responding and caused the firewall to reboot.
## PAN-113887
Fixed an issue where loading custom app tags did not complete successfully, which prevented subsequent requests (such as commits, content installs, and FQDN refreshes) from executing as expected.
## PAN-113870
Fixed an issue where Security policies were not evaluated in sequential order when the policy was based on URL categories.
## PAN-113796
Fixed an issue where GlobalProtect configured with the **pre-logon then on-demand** connect method was unable to authenticate during **pre-logon** when you configured the portal and gateway with an Authentication Override and without a certification profile.
## PAN-113767
Fixed an issue where the firewall silently dropped packets when security profiles were attached and FPGA enabled AHO and DFA.
## PAN-113619
Fixed an issue where the GlobalProtect gateway did not assign an IP address when the local IP address was a supernet of the GlobalProtect pool.
## PAN-113501
Fixed an issue where the Panorama management server returned a Security Copy (SCP) server connection error after you created an SCP Scheduled Config Export profile (**Panorama** > **Scheduled Config Export**) due to the SCP server password exceeding 15 characters in length.
## PAN-113229
Fixed an issue on Panorama M-Series and virtual appliances in an HA active/passive configuration where the passive firewall displayed an out-of-sync shared policy status when you edited the Device Group.
## PAN-113185
Fixed an issue where the passive firewall in an HA active/passive configuration was processing traffic.
## PAN-112988
Fixed an issue where a process (useridd) leaked memory, which caused the firewall to drop traffic and display the following error message: Out-of-memory condition detected, kill process.
## PAN-112972
Fixed an issue where scheduled reports were not generated as expected when you added groups in a query builder.
## PAN-112566
Fixed an issue where the GlobalProtect Client was unable to download files from a web interface, sessions went into DISCARD state, and displayed the following message: Packet dropped, control plane service not allowed.
## PAN-112529
Fixed an issue where the firewall incorrectly sent several benign critical content alerts daily.
## PAN-112467
Fixed an issue where obsolete IPv6 Neighbor Discovery (ND) entries did not clear as expected, which caused the IPv6 table to reach full capacity and caused new IPv6 ND entries to fail.
## PAN-112308
Fixed an issue where hardware security module (HSM) accounts were locked out after three attempts when you ran the show hsm ha-status CLI command.
## PAN-112016
Fixed an issue on VM-Series firewalls where the physical port counters on the dataplane interfaces did not increase on KVM when you disabled DPDK.
## PAN-111698
Fixed an issue where administrators were unable to log in when character spaces were used in usernames.
## PAN-111660
Fixed an issue where an incorrect SSH key initialization caused a process (pan_comm) to stop responding every 15 minutes when you configured an SSH proxy on the firewall.
## PAN-110990
Fixed an issue where a logical operation not configured with receive_time in the traffic log filter did not respond as expected.
## PAN-110960
Fixed an issue on Panorama M-Series and virtual appliances where commits failed when you configured an address group object in the Include List (**Network** > **Zone** > **<zone-name>** > **Include List**).
## PAN-110839
Fixed a rare issue where a commit pushed from Panorama failed, which caused a process (routed) to stop responding.
## PAN-110628
Fixed an issue where user groups were deleted from the Group Include List ("**Device** > **User identification** > **Group Mapping Settings** > **<group-name>** > **Group Include List**) if you changed the LDAP server profile account password.
## PAN-110234
Fixed an issue where administrators with a Superuser (read-only) role was able to initiate a commit through the CLI.
## PAN-110168
Fixed an issue where the firewall and Panorama web interface did not present HSTS headers to your web browser.
## PAN-109803
Fixed an issue where credential phishing prevention did not detect user or password phishing when passwords, which contained two discontiguous character spaces were used.
## PAN-109759
Fixed an issue where the firewall did not generate a notification for the GlobalProtect client when the firewall denied unencrypted TLS sessions due to an authentication policy match.
## PAN-107207
Fixed an issue where the VPN tunnel operational status incorrectly displays up even though the VPN tunnel is down.
## PAN-106889
Fixed a rare issue on a firewall in an HA active/passive configuration running in FIPS-CC mode where the passive firewall rebooted in to maintenance mode.
## PAN-106628
Fixed an issue where the firewall did not generate a system log when the firewall detected a RAM issue.
## PAN-106449
Fixed an issue when you connected to an internal GlobalProtect gateway on a firewall in an HA active/passive configuration and authenticated with multi-factor authentication (MFA) to access a resource, the first and second authentication factors succeeded but you would not be redirected to the actual resource.
## PAN-106100
```caveat
PA-3200 Series firewalls only
```
Fixed an issue on a firewall in an HA active/active configuration where SSL traffic through the GlobalProtect VPN (in SSL mode) tunnel stopped responding after Layer 7 processing completed and when asymmetric routing occurred.
## PAN-105286
Fixed an issue where the firewall did not record email header information in Data Filtering logs when you triggered a test mail that contained a data leak prevention (DLP) pattern.
## PAN-104909
Fixed an issue where the firewall incorrectly forwarded traffic when you configured the ingress interface with a QoS policy and the egress interface as a tunnel.
## PAN-104808
Fixed an issue where scheduled SaaS reports generated and emailed empty PDF reports.
## PAN-104251
Fixed an issue where the syslog server TCP keep-alive parameter caused the connection to unexpectedly age out.
## PAN-103865
Fixed an issue where the firewall did not detect user credentials when the number of users exceeded 60,000.
## PAN-103847
Fixed a memory buffer allocation issue that caused the Session Initiation Protocol (SIP) traffic NAT to stop responding.
## PAN-101613
```caveat
PA-800 Series firewalls only
```
Fixed an intermittent issue where a congestion condition occurred during periods of low traffic. With this fix, run the set system setting hol-system enable CLI command to enable the HOL system mode.
## PAN-84670
Fixed an issue where firewalls that were not configured to decrypt HTTPS services and applications traffic allowed users without valid authentication timestamps to access those resources regardless of Authentication Policy settings. To prevent such access, either configure the firewall to decrypt traffic or run the debug device-server cp-allow-encrypted-disable on command and execute a commit force CLI command (this command will persist across reboots).
@@ -0,0 +1,21 @@
---
type: Addressed
product: PAN-OS
version: 9.0.5-h3
---
## PAN-134242
```caveat
PA-7000 Series (PA-7000b with SMC-B) firewalls with Log Forwarding Cards (LFC) only
```
Fixed an issue related to incorrect restrictions on communications to the LFC.
## PAN-114784
Fixed an issue where a process (devsrvr) stopped responding after you pushed a configuration from Panorama™ to a firewall.
## PAN-111333
An enhancement was made to increase the pattern match limit to recognize applications and threats accurately.
@@ -0,0 +1,661 @@
---
type: Addressed
product: PAN-OS
version: 9.0.6
---
## WF500-5343
Fixed an issue on WF-500 that caused cloud queries to fail when the cloud verdict did not match the local verdict.
## PAN-135141
Fixed an issue where the Log Processing Card (LPC) did not come up intermittently in a fully loaded PA-7000 Series.
## PAN-134242
```caveat
PA-7000b Series firewalls with Log Forwarding Cards (LFC) only
```
A security fix was made to restrict improper communications to the LFC (CVE-2019-17440/PAN-SA-2019-0040).
## PAN-133883
Fixed an issue where a race condition caused pan_task and pan_com to exit unexpectedly.
## PAN-133491
Fixed an issue where Internet Protocol (IP) to user mappings were not synced from the HUB virtual system (vsys) to the non-hub vsys.
## PAN-133448
Fixed an issue where the mprelay process could crash during commit if the devsrvr process was restarted before or during the commit.
## PAN-133443
Fixed an issue where an XML API call incorrectly masked the response, which prevented role based administrators from running the response.
## PAN-132501
Fixed an issue where after you switched the **Context** from Panorama™ to a firewall, the DESTINATION ZONE (**Policies > Security > <policy-name> > Destination**) incorrectly displayed none.
## PAN-132104
Fixed an issue on Panorama M-Series and virtual appliances where the <show><object><registered-ip></registered-ip></object></show> XML API call did not retrieve more than 500 entries.
## PAN-131939
Fixed an issue where DP crashed during file transfer due to one or more content updates being installed.
## PAN-130640
Fixed an issue where the management plane CPU on the firewall was high due to index generation on summary logs.
## PAN-130465
Fixed an issue where required fields were masked incorrectly in a XML API call, which hid the response.
## PAN-130073
Fixed an issue where a large number (65,000) of GlobalProtect™ user connections caused a process (sslvpn) to stop responding after you upgraded from PAN-OS® 8.1.10 to PAN-OS 8.1.11.
## PAN-130069
Fixed an issue where the firewall incorrectly interpreted an external dynamic list MineMeld instability error code as an empty external dynamic list.
## PAN-129668
Fixed an issue on the firewalls where the dataplane restarted unexpectedly when processing HTTP/2 traffic if packet-diag debugs were enabled.
## PAN-129658
Fixed an issue where GTP inspection stopped functioning after unrelated changes in policy and a commit followed by a high availability (HA) failover.
## PAN-129441
Fixed an issue where the concurrent file limitation for WildFire® submissions didn't work when the firewall had many files waiting to be uploaded, which caused /opt/panlogs/wildfire/tmpfile to become full and destabilize the firewall (for example, the process crashed or system logs were not written).
## PAN-129327
Fixed a rare timing window that caused an Internal packet path monitoring failure.
## PAN-129127
Fixed an issue where log export from maintenance mode failed with the following error message: no ip address configured, can't export logs even though the management interface Internet Protocol (IP) address was configured.
## PAN-128856
Fixed an issue where the disk usage calculation was getting corrupted and purging logs.
## PAN-128269
```caveat
PA-5250, PA-5260, and PA-5280 firewalls with 100GB AOC cables only
```
Fixed an issue where after you upgraded the first peer in a high availability (HA) configuration to a PAN-OS 9.0 release, the High Speed Chassis Interconnect (HSCI) port did not come up due to an FEC mismatch until after you finished upgrading the second peer.
## PAN-128248
A fix was made to address a vulnerability with a race condition due to an insecure creation of a file in a temporary directory in PAN-OS ([CVE-2020-2016](https://security.paloaltonetworks.com/CVE-2020-2016)).
## PAN-127649
Fixed an issue where a purge script stopped responding, which caused a process (logrcvr) to discard incoming logs.
## PAN-127089
Fixed an intermittent issue where the default route did not redistribute to an OSPF Not-So-Stubby Area (NSSA).
## PAN-126882
A security fix was made to address an OpenSSL vulnerability (CVE-2019-1547/CVE-2019-1563).
## PAN-126627
Fixed an issue where a process (all_pktproc) stopped responding due to a NULL pointer exception while cleaning up SSL proxy sessions previously configured for GlobalProtect.
## PAN-126283
Fixed an intermittent issue where after you configured **Cache EDNS Responses** (**Network > DNS Proxy > <DNS Proxy-name> > Advanced**) a process (dnsproxy) stopped responding.
## PAN-126159
Fixed an issue where the firewall did not match the Security policy when you configured the match condition to a shared local group.
## PAN-125996
Fixed an issue on Panorama M-Series and VM-Series where the configd process would crash.
## PAN-125898
Fixed an issue where a process (openssl) caused higher than expected management CPU usage due to the incompletion of the Online Certificate Status Protocol (OCSP) during the logging service certificate validation.
## PAN-125793
Fixed an issue where multiple No valid URL filtering license warning messages were generated during a commit due to an expired URL filtering license. With this fix, the warning messages are grouped into a single message per virtual system (vsys).
## PAN-125594
Fixed an issue where the configd process on a Panorama appliance had a memory leak during commit operations.
## PAN-125302
Fixed an issue where the real-time clock (RTC) battery voltage exceeded the maximum threshold and triggered alerts in the system log.
## PAN-125157
Fixed an issue on the firewalls where the rasmgr process restarted unexpectedly when using third-party VPN clients to connect to GlobalProtect.
## PAN-125122
A fix was made to address a cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS and Panorama that disclosed an authenticated PAN-OS administrator's PAN-OS session cookie ([CVE-2020-2013](https://security.paloaltonetworks.com/CVE-2020-2013)).
## PAN-125018
Fixed an issue on Panorama M-Series and virtual appliances where after you configure the firewall with an API call commits took longer than expected.
## PAN-125017
```caveat
PA-7000b Series firewalls only
```
Fixed an issue where logs were unexpectedly discarded.
## PAN-124948
Fixed an issue where a null point (policy) dereference was causing a crash.
## PAN-124882
Fixed an issue where traffic logs that contained incorrect Security policies were generated during an active commit process when the Security policies were being added or removed.
## PAN-124858
Fixed an issue on PA-220, PA-820, and PA-850 firewalls where Custom Signatures caused the CTD memory depletion (OOM), which led to a dataplane crash.
## PAN-124781
Fixed an issue in Panorama where the **Policies > Security** web interface flashes and the selected security rule did not stay selected when making a change to a rule that was part of device group that included more than 200 rules.
## PAN-124593
A fix was made to address a missing XML validation vulnerability in the PAN-OS web interface ([CVE-2020-1975](https://security.paloaltonetworks.com/CVE-2020-1975)).
## PAN-124565
Fixed an issue where an out of memory condition caused commits to fail with the following error: Error unserializing profile objects failed to handle CONFIG_UPDATE_START.
## PAN-124435
Fixed an issue where the firewall dropped pre-VLAN spanning tree (PVST+) packets from the virtual wire interface when you executed the set session rewrite-pvst-pvid yes CLI command.
## PAN-124428
Fixed an issue where Address Resolution Protocol (ARP) randomly failed on one of the interfaces for a firewall deployed in the KVM/GCP/ESXi clouds.
## PAN-123857
Fixed an issue where HTTP/2 traffic inspection caused a software buffer leak over time and affected decryption traffic.
## PAN-123843
Fixed an issue for Cloud/VM platforms where the tunnels between the log collectors did not come up when a public IP was used for the log collectors in an environment with a Panorama management server and two or more log collectors.
## PAN-123747
Fixed an issue where App-ID™ signatures failed to match when there were more than 12 partial App-ID matches within the same session.
## PAN-123667
Fixed an issue where the snmpd process was crashing when polling for global counters.
## PAN-123661
A fix was made to address an authentication bypass vulnerability in the Panorama context switching feature ([CVE-2020-2018](https://security.paloaltonetworks.com/CVE-2020-2018)).
## PAN-123322
```caveat
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls running PAN-OS 9.0.5 only
```
Fixed an intermittent issue where a process (all_pktproc) stopped responding due to a Work Query Entry (WQE) corruption that was caused by duplicate child sessions.
## PAN-123306
Fixed an issue where the **Dashboard** did not display the release dates for Application Version, Threat Version, and Antivirus Version.
## PAN-123167
Fixed an issue where a process (mprelay) stopped responding.
## PAN-122788
Fixed an issue where the firewall incorrectly logged target filenames when an antivirus signature was triggered over a Server Message Block (SMB) protocol.
## PAN-122779
Fixed an issue where the firewall did not respond to TCP DNS requests when the firewall acted as a DNS proxy.
## PAN-122778
Fixed an issue where the routing daemon restarted due to a deadlock on the path monitoring heartbeat processing, leading to a SIGABRT.
## PAN-122565
Fixed an issue where a log collector with a dynamically assigned IP address could not establish communication between other log collectors.
## PAN-122455
Fixed an issue where the DHCP server incorrectly processed bootp unicast flag requests.
## PAN-122311
Fixed an issue where parent sessions were dropped when you installed duplicate predict session.
## PAN-122181
```caveat
PA-3200 Series and PA-5200 Series firewalls only
```
Fixed an issue where the firewall did not capture inbound Encapsulating Security Payload (ESP) protocol 50 packets at the receive stage.
## PAN-121917
```caveat
PA-800 Series and PA-220 firewalls only
```
Fixed an issue where the hrProcessorLoad.2 OID displayed incorrect values.
## PAN-121827
Fixed an issue where allow lists and auth profiles in multi-vsys systems would not allow a user to be identified in user groups.Users would show as **Not in allow list** because the multi-vsys (vsys1) was shown as **vsys0**.
## PAN-121609
```caveat
PA-7000 Series firewalls using PA-7000-20G-NPC cards only
```
Fixed an issue where the firewall restarted due to an internal path monitoring heartbeat failure during periods of more than expected traffic load.
## PAN-121484
```caveat
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
```
Fixed an issue where the dataplane sent positive acknowledgments to predict-status checks from FPP when the corresponding predict was deleted, which caused SIP and RTSP applications to perform less than the expected achievable performance.
## PAN-121481
Fixed an issue where downloading the GlobalProtect app software on your GlobalProtect portal took longer than expected.
## PAN-121472
Fixed an intermittent issue where the dataplane stopped responding when processing compressed traffic.
## PAN-121374
Fixed an issue where Internet Protocol (IP) tags with timeouts generated alert messages.
## PAN-121184
Fixed an issue where the varrcvr process crashed due to memory corruption issues.
## PAN-121058
A fix was made to address a DOM-based cross site scripting vulnerability in the PAN-OS and Panorama management web interfaces ([CVE-2020-2017](https://security.paloaltonetworks.com/CVE-2020-2017)).
## PAN-121022
Fixed an issue involving unexpected behavior within the GlobalProtect app where the Active viewed Template does not populate when clicking the hyperlink to trigger a redirect to the Template area and list.
## PAN-120986
Fixed an issue where a process (routed) stopped responding when you configured virtual interfaces.
## PAN-120965
Fixed an issue where certificate revocation list (CRL) and Online Certificate Status Protocol (OCSP) checks did not respond as expected when you configured **Block session if certificate status is unknown**.
## PAN-120909
Fixed an issue to improve the validation of certain field inputs in the web interface.
## PAN-120900
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where after you submitted a host information profile (HIP) report a duplicate User-ID™ log was generated on the passive firewall.
## PAN-120893
Fixed an issue where the Security Parameter Index (SPI) size was incorrectly set in the IKE Phase 2 packet when you configured commit-bit on the neighboring device, which caused IKE negotiations to fail on the neighboring device.
## PAN-120730
Fixed an issue where pushing a config bundle from Panorama M-Series to a firewall failed with the following error: log-card -> iptag unexpected here.
## PAN-120701
Fixed an issue where URL filtering blocked web traffic by the security policy that did not have URL filtering enabled.
## PAN-120665
(PA-800 Series) Fixed an issue where the deployment of the Master Key through the web interface failed.
## PAN-120545
Fixed an issue on VM-Series firewalls where the ager ran faster than expected, which prematurely caused the master key to expire.
## PAN-120420
Fixed an issue in Panorama where you could not see **Certificate Profile** in the drop-down when adding an HTTP Server Profile.
## PAN-120397
A fix was made to address an external control of path and data vulnerability in the Palo Alto Networks Panorama XSLT processing logic ([CVE-2020-2001](https://security.paloaltonetworks.com/CVE-2020-2001)).
## PAN-120351
Fixed an issue where the firewall caused unnecessary fragmentation when traffic and tunnel were content inspected, which caused retransmission and slowed response time.
## PAN-120300
Fixed an issue where you were unable to view DHCP leases from the web interface or through the show dhcp server lease interface all CLI command due to the request taking longer than expected, which resulted in a time out.
## PAN-120157
Fixed an issue where temporary files created on a firewall during an API call execution were not properly cleaned up, leading to increased disk space usage.
## PAN-120106
Fixed an issue where Panorama did not send correlation events and logs to the syslog server after you upgraded the firewall from PAN-OS 8.0.9 to PAN-OS 8.1.7.
## PAN-120005
Fixed an issue where the firewall incorrectly forwarded incomplete and corrupted files through the Server Message Block (SMB) protocol to WildFire. This fix requires content release version 8219 or a later version.
## PAN-119950
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where a process (flow_ctrl) received and restarted due to a malformed ICMPv6 neighbor advertisement packet.
## PAN-119922
Fixed an issue in Panorama where the show config diff command was not working correctly and produced unexpected output.
## PAN-119822
Fixed an issue where you were not redirected to the application URL after authentication.
## PAN-119820
Fixed an issue where the firewall incorrectly calculated the TCP segment size when performing forward proxy decryption.
## PAN-119819
Fixed an issue where **Discover** (**Device > User Identification > User Mapping > Server Monitoring**) stopped responding after you configured a DNS proxy.
## PAN-119818
Fixed an issue where corrupt logs caused buffered log forwarding to stop responding.
## PAN-119801
Fixed an issue where the firewall web interface did not display the BGP **MED** attribute value in the BGP **Rib-Out** tab (**Virtual Routers > More Runtime Stats**).
## PAN-119550
Fixed an issue on Panorama M-Series and virtual appliances where communication between two processes (mgmtsrvr and logd) stopped responding.
## PAN-119545
Fixed an issue where updates (including WildFire, antivirus, and so on) were intermittently failing.
## PAN-119452
An enhancement was made to improve subsequent loading times of device groups after the first load.
## PAN-119349
Fixed an issue on Panorama M-Series and virtual appliances where custom reports from the User-ID log displayed the incorrect receive date.
## PAN-119343
Fixed an issue where a daemon (dnsproxy) incorrectly handled TCP requests, which caused the daemon (dnsproxy) to stop responding.
## PAN-119047
Fixed an issue where local user group names that contained upper case characters were not converted to lower case characters prior to encoding, which caused the firewall not to load user groups names with upper case characters.
## PAN-119046
Fixed an issue where moving multiple rules in Panorama using the **Move All rules in Group** and **Move rules in group to different rule base** group actions caused the rules to move in a reversed order.
## PAN-118991
Fixed an issue in Panorama where on a high availability (HA) pair working in legacy mode, the following error message displayed in the system log: Panorama has lost connection to its peer, no log will be forwarded.
## PAN-118957
A fix was made to address an authentication bypass spoofing vulnerability in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS ([CVE-2020-2002](https://security.paloaltonetworks.com/CVE-2020-2002)).
## PAN-118851
Fixed an issue where the BGP Conditional Advertisement suppress condition was not met, which caused the **Conditional Adv** (**Network > Virtual Routers > <router-name> > BGP**) not to apply the NEXT HOPS prefix range.
## PAN-118777
Fixed an issue on a firewall in a high availability (HA) active/active configuration where larger than expected packets sizes were silently dropped when traversing through an HA3 link in an asymmetric network.
## PAN-118436
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where applications using the GlobalProtect Clientless VPN did not respond when the Clientless VPN used a VLAN interface.
## PAN-118413
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where the show system logd-quota CLI command did not display the Session log storage Quotas as expected.
## PAN-118259
Fixed an issue where you were unable to generate WildFire analysis reports in the WildFire Submissions log when you configured **Proxy Server** (**Device > Setup > Services > Global**).
## PAN-118249
Fixed an issue where traffic logs and URL Filtering logs did not display the URL for decrypted traffic.
## PAN-118207
Fixed an issue where the Security Assertion Markup Language (SAML) for GlobalProtect did not respond as expected when you configured the IdP certificate as **None** on the SAML IdP server profile.
## PAN-118108
Fixed an issue where an API call against a Panorama management server, which triggered the request analyze-shared-policy command, caused Panorama to reboot after you executed the command.
## PAN-118091
Fixed an issue where application dependency warnings were displayed after a commit when the policy rules containing the dependent applications used different sources (one used user and the other used groups).
## PAN-118090
Fixed an issue on Panorama M-Series and virtual appliances where **User Activity Report** (**Monitor > PDF Reports**) did not generate reports as expected.
## PAN-118075
Fixed an issue where the BGP conditional advertisement did not respond as expected, which caused the prefix in the **Advertise Filters** (**Network > Virtual Router > BGP > Conditional Adv**) to be incorrectly advertised.
## PAN-118050
Fixed an issue where some packets had incorrect timestamps in the transmit stage during packet capture.
## PAN-117987
Fixed an issue where the firewall did not exclude video traffic from the GlobalProtect tunnel when you configured **Exclude video traffic from the tunnel (Windows and macOS only)** (**Network > GlobalProtect > Gateways > <gateway-name> > Agent > Video Traffic**).
## PAN-117969
An enhancement was made to enable administrators to select signature and digest algorithms for outgoing Security Assertion Markup Language (SAML) messages through a CLI command.
## PAN-117774
Fixed an Issue where the dataplane stopped responding due to an incorrect parsing of cookies for GlobalProtect Clientless VPN applications.
## PAN-117736
Fixed an issue on a firewall in a high availability (HA) active/active configuration where virtual MAC addresses pushed from Panorama were overridden on the local firewall.
## PAN-117561
Fixed an issue in Panorama where **Packet Capture** was enabled with **extended-capture** (**Objects > Security Profiles > Anti-Spyware**) for DNS signatures, but the setting was not pushed to firewalls running PAN-OS 8.1.
## PAN-117479
A fix was made to address a vulnerability with the Nginx web server included with PAN-OS ([CVE-2017-7529](https://security.paloaltonetworks.com/CVE-2017-7529)).
## PAN-117463
Fixed an issue where the firewall did not release the default DHCP route when a new IP address was obtained on a DHCP configured interface.
## PAN-117446
Fixed an issue where GlobalProtect authentication failed when you used the domain in the group mapping and a User Principle Name (UPN) format for authentication.
## PAN-117276
Fixed an issue on a firewall in a high availability (HA) active/active configuration where the names of the virtual routers were pushed from the active-primary firewall to the active-secondary firewall when you sync the configuration, which caused schema verification to stop responding when you do a local commit on the active-secondary firewall.
## PAN-117251
Fixed an issue where vsysadmins were unable to view the locks on all the virtual systems they were assigned to. To view the locks in CLI run the new show commit-locks vsys and show config-locks vsys CLI commands.
## PAN-117167
Fixed an issue where a process (configd) exceeded the memory limit and stopped responding.
## PAN-116889
Fixed an issue where you were unable to establish an SSH session through a CLI command using a Diffie-Hellman (DH) algorithm.
## PAN-116841
Fixed an issue where commits failed when address objects were used in static route configurations.
## PAN-116615
Fixed an issue where authentication failed for newly added groups in the authentication profile Allow List.
## PAN-116383
Fixed an issue with Panorama on AWS where the configuration of the high availability (HA) pair became out of sync due to different plugin versions being detected even though the same versions were installed on both peers.
## PAN-116355
```caveat
PA-5200 Series firewalls only
```
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where an HA1 heartbeat backup connection flap occurred and displayed the following error message: ha_ping_send/No buffer space available.
## PAN-116173
Fixed an intermittent issue on a firewall in a high availability (HA) active/passive configuration where traffic interruptions occurred until you triggered a manual failover.
## PAN-116100
Fixed an issue where a process (mprelay) stopped responding and invoked an out-of-memory (OOM) killer condition and displayed the following error messages: tcam full and pan_plfm_fe_cp_arp_delete.
## PAN-115875
Fixed an issue where a PA-7080b HA pair rebooted when large sized packet traffic impacted the front panel ports of the Log Forwarding Card (LFC).
## PAN-115238
Fixed an issue where SSL renegotiation sessions incorrectly identified URL categories.
## PAN-115018
Fixed an issue where the firewall was unable to access the CPU information and caused the CPU frequency to set to 0, which resulted in a divide by zero error and caused a process (devsrvr) to stop responding.
## PAN-114966
Fixed an issue where trunk interfaces were not working on Hyper-V.
## PAN-114784
Fixed an issue where a process (devsrvr) stopped responding after you pushed a configuration from Panorama to a firewall.
## PAN-114438
Fixed an issue where the system log incorrectly reported intermittent certificate revocation list (CRL) fetches as successful even though the fetches were not successful.
## PAN-114197
Fixed an issue where a configured certificate profile was not visible from the web interface in **Network > Network Profiles > IKE Gateways > Add > General > Certificate Profile**.
## PAN-113144
Fixed an issue where BGP peers were not enabled when transitioning from Active/Passive to Active/Active or Active/Active to Active/Passive config on both IPv4 and IPv6 peer groups.
## PAN-112145
Fixed an intermittent issue where a process (useridd) incorrectly reported successful Ops commands and did not download Dynamic Address Group updates, which prevented virtual machines from updating Dynamic Address Groups.
## PAN-111650
Fixed an issue where a process (mgmtsrvr) stopped responding when another process (masterd) sent a signal interruption after you upgraded from a PAN-OS 9.0 release to a PAN-OS 9.1 release.
## PAN-111333
An enhancement was made to increase the pattern match limit to recognize applications and threats accurately.
## PAN-111135
Fixed an issue where Panorama displayed incorrect device monitoring values (**Panorama > Managed Devices > Health**) for the firewall.
## PAN-109528
Fixed an issue where an old GPRS tunneling protocol (GTP) event was unexpectedly freed when an update message arrived, causing a crash.
## PAN-109406
Fixed an issue where the firewall restarted when you unplugged the QSFP+ module from the High Speed Chassis Interconnect (HSCI) port.
## PAN-108992
A fix was made to address an improper authorization vulnerability in PAN-OS ([CVE-2020-1998](https://security.paloaltonetworks.com/CVE-2020-1998)).
## PAN-107358
Fixed an issue where a firewall had a race condition in the error handling code in the write thread, causing memory corruption in the sslmgr session cache ring buffer.
## PAN-105763
An enhancement was made to enable you to set the signing algorithm to **sha-1** or **sha-256** in the Security Assertion Markup Language (SAML) message on the firewall.
## PAN-100946
Fixed an issue where VM-Series firewalls were unable to support the maximum number of tunnel interfaces due to less than expected memory allocation.
## PAN-95651
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where incomplete core dump files were generated during dataplane process crashes, making the crash analysis difficult.
## PAN-71148
Fixed an issue on Panorama where the **ACC** tab would not show data for the period before the daylight saving time (DST) change.
@@ -0,0 +1,465 @@
---
type: Addressed
product: PAN-OS
version: 9.0.7
---
## WF500-5185
```caveat
WF-500 Series only
```
Fixed an issue where high disk use was observed due to an inadequate rotation of log files.
## PAN-140090
Fixed an issue where HA links were down in VLAN access mode for KVM. This fix is only applicable for KVM deployments that are configured in VLAN access mode with SR-IOV.
## PAN-137458
Fixed an issue where system logs with new event IDs caused a memory leak in a process (mgmtsrvr).
## PAN-136698
Fixed an issue where a process (all_pktproc) stopped responding and the dataplane restarted when the firewall processed a malformed GPRS tunneling protocol (GTP) packet.
## PAN-136696
Fixed an issue where the dataplane restarted due to excessive logs from the pan_comm process.
## PAN-135703
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where the switch ports connected to Quad Small Form-factor Pluggable (QSFP+) interfaces were up while Network Processing Cards (NPCs) were still rebooting.
## PAN-135260
```caveat
PA-7000 Series firewalls running PAN-OS® 8.1.12 only
```
Fixed an intermittent issue where the dataplane process (all_pktproc_X) on a Network Processing Card (NPC) restarted when processing IPSec tunnel traffic.
## PAN-135103
A fix was made to address a format string vulnerability on PA-7000 Series firewalls with a Log Forwarding Card (LFC) ([CVE-2020-1992](https://security.paloaltonetworks.com/CVE-2020-1992)).
## PAN-135089
Fixed an issue where the CPU for a process (ikemgr) spiked when third-party VPN clients connected to the GlobalProtect gateway with more than three DNS servers configured.
## PAN-134678
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where the Quad Small Form-factor Pluggable (QSFP) 28 ports 21 and 22 did not respond when plugged in with a Finisar 100G AOC cable.
## PAN-134370
Fixed an issue where a process (mp-relay) restarted due to missing routes or next hops.
## PAN-134244
Fixed an issue where connections proxied by the firewall (such as SSL Decryption, GlobalProtect portal and gateway connections, and SIP over TCP) failed due to insufficient buffer allocation. Some connections failed with the following error message: proxy decrypt failure.
## PAN-133582
Fixed an issue in the firewalls where some Dynamic Address Groups pushed from Panorama were missing member IP addresses.
## PAN-133440
Fixed an issue where fragmented traffic caused high dataplane use and firewall performance issues.
## PAN-133378
Fixed an issue in Panorama where a process (configd) restarted while doing a commit using a RADIUS super admin role.
## PAN-133048
```caveat
PA-5200 and PA-7000 Series firewalls only
```
Fixed an issue where firewalls processed traffic asymmetrically when using Internet Protocol (IP) classifiers on virtual wire (vwire) subinterfaces.
## PAN-133042
```caveat
PA-5200 and PA-7000 Series firewalls only
```
Fixed an issue where firewalls dropped certain GPRS tunneling protocol (GTP) traffic even when gtp nodrop was enabled.
## PAN-133040
Fixed an issue on a WF-500 appliance where a VM-Series firewall controller stopped responding, which caused the appliance to stop file analysis.
## PAN-131993
Fixed an issue where a process (reportd) would crash while running a log query.
## PAN-131907
Fixed an issue where GPRS tunneling protocol (GTP) version 2 handling was unable to handle fully qualified tunnel endpoint IDs (FTEID) received in reverse order, which resulted in GTP-C and GTP-U flows with incorrect IP addresses and tunnel endpoint IDs (TEID). This caused a GTP stateful inspection failure for subsequent packets on the respective flows.
## PAN-131486
Fixed an issue where autocommits failed due to invalid access routes after an upgrade.
## PAN-131193
Fixed an issue where firewalls dropped generic routing encapsulation (GRE) packets with the following error message: Packet dropped, prepend failure.
## PAN-130573
Fixed an issue where the software pool for Regex results was depleted and caused connection failures.
## PAN-130447
Fixed an issue where the firewall dropped offloaded traffic every time there was an explicit commit (**Commit** on the firewall locally or **Commit All Changes** in Panorama) or an implicit commit (such as an Antivirus update, Dynamic Update, or WildFire® update) on the firewall.
## PAN-130361
A fix was made to address an external control of filename vulnerability in the SD-WAN component of Palo Alto Networks Panorama ([CVE-2020-2009](https://security.paloaltonetworks.com/CVE-2020-2009)).
## PAN-130345
Fixed an issue where the Panorama VM rebooted while filtering for configuration logs when the query value was not one of the predefined string results.
## PAN-130290
Fixed an issue in the web interface where traffic logs did not display the destination zone (**Monitor > Logs > Traffic > To Zone**) for multicast sessions.
## PAN-130262
Fixed an issue where firewalls dropped HTTP 200 OK messages during the offload of traffic for App-ID™ inspection.
## PAN-130229
Fixed an issue on Panorama appliances where you could not change maximum transmission unit (MTU) values from the web interface; attempting to do so caused the appliance to display the following error message: Malformed Request.
## PAN-129518
Fixed an issue where the firewall restarted due to an out-of-memory (OOM) condition caused by a leak in a process (ikemgr).
## PAN-129490
Fixed an issue where CRL/OCSP verifications failed due to requests routing through the management interface even when service route was configured.
## PAN-128908
If a user password was changed but no commit was performed afterward, the new password did not persist after a reboot. Instead, the user could still use the old password to log in, and the calculation of expiry days was incorrect based on the password change timestamp in the database.
## PAN-128717
Fixed an issue in Panorama where, after switching context to a managed device, the session idle timeout was not updated, and the web session timed out even while the administrator was actively working in the interface.
## PAN-127616
Fixed an issue where you could not push **FQDN Minimum Refresh Time** from Panorama to managed firewalls.
## PAN-127438
Fixed an issue where GlobalProtect portal configuration selection based on certificate template OID failed.
## PAN-127219
Fixed an issue where you could not select existing certificates when creating an authentication profile by using the Security Assertion Markup Language (SAML) method on the template stack.
## PAN-127118
A fix was made to address an OS command line injection vulnerability in the PAN-OS management server where authenticated users were able to inject arbitrary shell commands with root privileges ([CVE-2020-2014](https://security.paloaltonetworks.com/CVE-2020-2014)).
## PAN-127087
Fixed an issue where a push operation (**Commit All Changes**) from Panorama failed on passive firewalls when pushing a large number of new Security policy rules to both firewalls in a high availability (HA) pair.
## PAN-126944
Fixed an issue where the Panorama Template did not allow for **Ethernet Interface Link Speed** configurations greater than 1,000Mpbs.
## PAN-126817
Fixed an issue where Security Assertion Markup Language (SAML) response validation failed with a certificate mismatch error even if the firewall had the same certificate on IdP.
## PAN-126775
```caveat
PA-800 and PA-220 Series only
```
Fixed an issue where NTP sync failures occurred when using NTP servers configured with IPv6.
## PAN-126573
Fixed an issue on Panorama where, after overriding a Layer 3 **Aggregate Group** subinterface, all subinterfaces in the stack template disappeared.
## PAN-126412
Fixed an issue where hardware security model (HSM) authentication from the web interface failed if the password contained an ampersand (&).
## PAN-126362
A fix was made to address a command injection vulnerability in the PAN-OS management interface where an authenticated administrator was able to execute arbitrary OS commands with root privileges ([CVE-2020-2010](https://security.paloaltonetworks.com/CVE-2020-2010)).
## PAN-126278
Fixed an issue where a burst of VLAN-tagged packets in a congested system caused an overflow and locked up the firewall. With this fix, the threshold is increased.
## PAN-126202
Fixed an issue where a process (routed) stopped responding when users accessed the web interface to view the OSPF interface data (**Network > Virtual Routers > More Runtime Stats > OSPF > Interface**) if OSPF MD5 was configured in the OSPF Auth profile.
## PAN-126017
Fixed an issue where the set application dump on rule CLI command did not accept rule names with more than than 32 characters despite a stated limit of 63 characters.
## PAN-126014
Fixed an issue for GlobalProtect gateways where the **Login At** and **Logout At** time fields in the **Previous User** PDF/CSV report for **User Information** used the Epoch standard for displaying time.
## PAN-125889
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where auto-tagging in log forwarding didn't work.
## PAN-125804
A fix was made to address an issue where an OS command injection vulnerability in the PAN-OS management server allowed authenticated administrators to execute arbitrary OS commands with root privileges when uploading a new certificate in FIPS-CC mode ([CVE-2020-2028](https://security.paloaltonetworks.com/CVE-2020-2028)).
## PAN-125546
Fixed an issue where a process failed to restart even when the system logs displayed the following message: virtual memory exceeded, restarting.
## PAN-125527
Fixed an issue where a multilayer ZIP file inspection caused software buffer corruption and the all_pktproc process to restart.
## PAN-125306
Fixed an issue where a Transmission Control Protocol (TCP) connection reuse was incorrectly handled by an HA active/active cluster with asymmetric flows.
## PAN-125194
Fixed an issue where system startup failed when the collector group was configured with an incorrect serial number of invalid length.
## PAN-125032
Fixed an issue where, when **Minimum Password Complexity** was **Enabled** for all local administrators, the setting was also applied to plugin users. This caused API calls from plugin users to fail (HTTP Error code 502) because the password change was not made for the users which caused authentication to fail.
## PAN-124857
Fixed an issue where a Microsoft Access Database (MDB) file stopped and a process (mgmtsrvr) stopped responding at the epoll_wait () system call after the Panorama Virtual Appliance was stopped and started from Azure.
## PAN-124802
Fixed an issue where LACP connectivity issues were observed due to high CPU utilization when multiple dataplanes were used.
## PAN-124628
Fixed an issue where REST API queries were unable to pull shared region objects on Panorama.
## PAN-124495
Fixed an issue on Panorama where the task manager showed locally executed jobs but did not show tasks or jobs pushed to managed firewalls.
## PAN-124087
Fixed an issue where GPRS tunneling protocol (GTP) v2 protocol handling failed to handle the secondary Modify Bearer Request/Response in the GTP-C session.
## PAN-123858
Fixed an issue on firewalls where a process (userid) restarted while processing incorrect IP address-to-username mappings that contained blank usernames from User-ID agents.
## PAN-123830
Fixed an issue where the GlobalProtect™ portal used an outdated getbootstrap version.
## PAN-123736
Fixed an issue where a Create Session Request message looped internally, which caused continuous packet inspection that consumed firewall resources.
## PAN-123724
Fixed an issue in Panorama where shared address objects were not configurable as a destination in a static route configuration.
## PAN-123391
A fix was made to address a predictable temporary file vulnerability in PAN-OS ([CVE-2020-1994](https://security.paloaltonetworks.com/CVE-2020-1994)).
## PAN-123295
Fixed an issue where the dataplane restarted due to a race condition when a configuration push and a Netflow update occurred simultaneously.
## PAN-123135
Fixed an issue where user group membership lookup failed if the username source (for example, Security Assertion Markup Language identity provider (SAML IdP)) did not provide the user domain information. The issue occurred even if you configured the firewall to **Allow matching usernames without domains** (**Device > User Identification > User Mapping > Palo Alto Networks User-ID Agent Setup**).
## PAN-122909
Fixed an issue where enabling **SSL Forward Proxy** using the hardware security module (HSM) led to intermittent failures when loading random secure websites and displayed the following message: ERR_CERT_INVALID. This issue was most closely associated with servers presenting ECDSA certificates.
## PAN-122872
Fixed an issue where the Aggregate Ethernet (AE) subinterface showed a different status from the AE parent interface.
## PAN-122147
Fixed an issue where the firewall dropped IPv6 Bidirectional Forwarding Detection (BFD) packets due to a race condition with the Neighbor Discovery Protocol (NDP).
## PAN-121822
Fixed an issue with certificate authentication where only the topmost certificate was used to validate the client certificate.
## PAN-121654
```caveat
PA-3000 Series firewalls only
```
Fixed an issue where decrypting HTTP/2 traffic caused performance issues due to low memory conditions.
## PAN-121626
```caveat
PA-3200 Series firewalls only
```
Fixed an intermittent issue where firewalls dropped packets, which caused issues such as traffic latency, slow file transfers, reduced throughput, internal path monitoring failures, and application failures.
## PAN-121598
Fixed an issue where the PAN-OS XML API packet capture (pcap) export failed with the following error message: Missing value for parameter device_name. Now, device_name and sessionid are no longer required parameters.
## PAN-121596
Fixed an issue where the OSPF protocol didn't choose the correct loopback address for the forwarding address in the Not-So-Stubby Area (NSSA).
## PAN-121483
Fixed an issue where Data Filtering profiles did not generate a packet capture (pcap) for Server Message Block (SMB) when action was set to Alert.
## PAN-121395
Fixed an issue where the bidirectional static NAT policy rule hit count did not increase even when the policy was used.
## PAN-121371
Fixed an issue where autocommit stopped at 99% if the firewall had an invalid customer ID.
## PAN-121319
A fix was made to address a stack-based buffer overflow vulnerability in the management server component of PAN-OS ([CVE-2020-1990](https://security.paloaltonetworks.com/CVE-2020-1990)).
## PAN-121258
Fixed an issue where some SSLv3 session traffic logs showed an Allow action even when the security rule policy had a Deny action when url-proxy was enabled.
## PAN-120726
Fixed an issue where the firewall incorrectly populated the username after the user was served an Anti-Phishing Continue page due to credential phishing detection.
## PAN-120640
Fixed an issue where show routing bfd related commands triggered a memory leak in a process (routed).
## PAN-120350
Fixed an issue where an Address Resolution Protocol (ARP) broadcast storm overloaded the Log Processing Card (LPC) and caused the device to reboot.
## PAN-119810
A fix was made to address the improper restriction of the XML external entity (XXE) vulnerability in the Palo Alto Networks Panorama management server ([CVE-2020-2012](https://security.paloaltonetworks.com/CVE-2020-2012)).
## PAN-119625
Fixed an issue where configuring GlobalProtect certificate enrollment using Simple Certificate Enrollment Protocol (SCEP) with a dynamic SCEP challenge caused the firewall to initiate a TLS 1.0 based connection for challenge authentication.
## PAN-119442
Fixed an issue where Panorama did not display the drop-down for part of a custom report after using **Pick up Later** (**Monitor > Manage Custom Reports**).
## PAN-119173
```caveat
PA-5000 and PA-3000 Series firewalls only
```
Fixed an issue where the passive device in a high availability (HA) pair started processing traffic, which resulted in a packet buffer leak.
## PAN-118226
A fix was made to address an improper input validation vulnerability in the configuration daemon of Palo Alto Networks Panorama ([CVE-2020-2011](https://security.paloaltonetworks.com/CVE-2020-2011)).
## PAN-117480
A fix was made to upgrade Nginx software included with PAN-OS ([PAN-SA-2020-0006](https://security.paloaltonetworks.com/PAN-SA-2020-0006) / CVE-2016-4450 and CVE-2013-0337).
## PAN-117108
Fixed an issue where user mappings populated by the XML API were lost after a reboot.
## PAN-117043
Fixed an issue where using special characters in the tag names of the Security policy rules returned the following error message when committing or pushing a configuration: group-tag is invalid.
## PAN-116842
Fixed an issue where, after enabling a Cortex Data Lake license, the management plane memory utilization would increase unexpectedly when some connections between the firewall and Customer Support Portal server were blocked, leading to multiple process restarts due to an out-of-memory (OOM) condition.
## PAN-116231
Fixed an issue where invalid packet header content drop counters were seen in global counters when packets from the network or HA3 were hitting a stale flow. The following flow state verify error was seen: flow_fpga_rcv_key_err - Packets dropped.
## PAN-116061
Fixed an issue where traffic traversing through an IPSec tunnel used did not use the default maximum interface bandwidth, which caused the traffic to traverse through the IPSec tunnel with latency.
## PAN-116002
Fixed an issue where an incorrect optimization could cause IP address-to-user mapping to not update within 60 seconds.
## PAN-115562
Fixed an issue where superuser CLI permissions for role-based administrators did not match superuser privileges.
## PAN-115093
Fixed an issue where the firewall generated excessive logs for content decoder (CTD) errors.
## PAN-114648
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the HA1 hearbeat backup connection flapped due to ping failures caused by unavailable buffer space when **Heartbeat Backup** was configured (**Device > High Availability > Election Settings**).
## PAN-111636
A fix was made to address OpenSSH issues ([PAN-SA-2020-0002](https://security.paloaltonetworks.com/PAN-SA-2020-0002) / CVE-2018-20685, CVE-2019-6109, and CVE-2019-6111).
## PAN-102682
A fix was made to address an OS command injection vulnerability in the management component of PAN-OS where an authenticated user was able to potentially execute arbitrary commands with root privileges ([CVE-2020-2007](https://security.paloaltonetworks.com/CVE-2020-2007)).
## PAN-100734
A fix was made to address a buffer flow vulnerability in the PAN-OS management interface where authenticated users were able to crash system processes or execute arbitrary code with root privileges ([CVE-2020-2015](https://security.paloaltonetworks.com/CVE-2020-2015)).
## PAN-100415
A fix was made to address an external control of filename vulnerability in the command processing of PAN-OS ([CVE-2020-2003](https://security.paloaltonetworks.com/CVE-2020-2003)).
## PAN-74442
Fixed an issue where, after enabling debugging on the dataplane, the debug logs contained information about unrelated traffic.
@@ -0,0 +1,201 @@
---
type: Addressed
product: PAN-OS
version: 9.0.8
---
## PAN-140575
Fixed an issue where a process (masterd) did not restart another process (logrcvr) on the Log Forwarding Card (LFC) after the process (logrcvr) crashed.
## PAN-140509
Fixed an issue where performing private data resets during custom Amazon Machine Image (AMI) creation removed CloudWatch directories and caused the CloudWatch plugin to fail.
## PAN-140270
Added additional debugging to periodically collect the debug dataplane internal pdt bcm counters graphical CLI command's output in the Tech Support File (TSF).
## PAN-140043
```caveat
PA-7050 firewalls running on PA-7000 100G NPCs only
```
Fixed an issue where the PA-7000 100G NPC Native Implemented Function (NIF) initialization took longer than expected, which caused internal path monitoring failure and sent the firewall into a non-functional state while rebooting.
## PAN-139555
Fixed an issue where after upgrading the passive firewall, the outer UDP sessions synced from the active firewall did not retain the rule information and after failover, GPRS tunneling protocol (GTP) inspection did not work.
## PAN-137673
Fixed an issue where a memory leak associated with a process (devsrvr) caused an out-of-memory (OOM) condition on the firewall.
## PAN-136765
Fixed an issue where an FQDN update that resolved to the same IP address of another FQDN across different policies caused the other FQDN to be deleted due to missing FQDN aggregation.
## PAN-136612
Fixed an issue where fragmented packets leaked, which caused the depletion of Work Query Entry (WQE) pools.
## PAN-136470
Fixed an issue where a process (all_pktproc) restarted while processing packets with 0.0.0.0 and destination protocol 251 that internally mapped to GTP-C traffic, which caused the dataplane to restart.
## PAN-136173
Fixed an issue where dataplane interfaces remained down after active firewall bootup or a high availability (HA) failover.
## PAN-135909
Fixed an issue where connections to the web interface were abruptly interrupted due to a double free condition (gPanUiPhpGlobal_secure_config_reset), which led to unexpected process restarts.
## PAN-134571
Fixed an issue where DNS security incorrectly set bits to zero on compressed DNS packets, which caused DNS malformation.
## PAN-134547
Fixed an issue where the passive firewall in an active/passive HA configuration deleted BGP-learned routes synchronized from the active firewall if the BGP configuration included the redistribution of the learned routes.
## PAN-134546
Fixed a rare issue on the firewall where a process (flow_mgmt) restarted due to an invalid packet received through the GlobalProtect agent or clientless VPN.
## PAN-134431
Fixed an issue with Security Assertion Markup Language (SAML) authentication where the firewall used old authd_id values, which resulted in failed authentication.
## PAN-133289
Fixed an issue where improper parsing of the URL database caused high device-server CPU usage.
## PAN-132898
Fixed an intermittent issue where logs were missing with log_index debug messages due to merging of the index.
## PAN-132651
Fixed an issue where packet buffer use was at 99% and tunnel monitoring failed, which caused tunnel flaps and LDAP authentication failures.
## PAN-131922
Fixed an issue where the certificate was not automatically pushed to the firewall until you manually fetched the certificate from the firewall.
## PAN-131517
Fixed an issue with a memory corruption error that caused a process (all_pktproc) to restart.
## PAN-130750
Fixed an issue where commit failed on the firewall after disabling **Pre-Defined Reports** from Panorama.
## PAN-129328
Fixed an issue where packet descriptor (on-chip) usage reached 100% even though buffers, throughput, and session counts were not elevated.
## PAN-129289
Fixed an issue where export failed for a large running-config.xml file using the XML API.
## PAN-128568
Fixed a rare issue on the firewalls where a process (pan_task) restarted due to NULL pointer exception.
## PAN-128330
Fixed an issue where the response for the XML API call for the show object registered-ip all operational CLI command included extra appended content.
## PAN-128195
Fixed an issue on Panorama where processes (vld) ran on high CPU when the incoming system log rate was 0.
## PAN-127614
Fixed an issue where SNMPv3 monitoring of the firewall failed from the Zabbix server after a firewall reboot or SNMP daemon restart on the firewall.
## PAN-127358
Fixed an issue with a memory leak in a process (configd) where virtual memory exceeded the limit, which caused the process to restart.
## PAN-127318
Fixed an issue where the firewall intermittently dropped DNS A or AAAA queries received over IPSec tunnels due to a session installation failure.
## PAN-127004
Fixed an issue where a process (sysd) restarted due to missing heartbeats.
## PAN-126205
Fixed an issue where role-based administrators were unable to import certificate private keys onto firewalls.
## PAN-126069
Fixed an issue in Panorama where logs couldn't be viewed when an additional log collector was configured in the existing log collector group.
## PAN-125934
Fixed an issue on Panorama where a commit failed when bootstrapping a firewall to a configuration with a serial number of "unknown." The commit failed with the following error message: mgt-config -> devices -> unknown unknown is invalid.
## PAN-125794
Fixed an issue where a role-based administrator with CLI access was not able to successfully execute the commit-partial CLI command to commit only changes made by themselves.
## PAN-125730
Fixed an issue where packets tagged with IP protocol 252 were incorrectly treated as GPRS tunneling protocol (GTP) traffic, which caused the packet processor to terminate.
## PAN-125534
```caveat
PA-5200 Series and PA-7000 Series firewalls only
```
Fixed an issue where firewalls experienced high packet descriptor (on-chip) usage during uploads to the WildFire Cloud or WF-500 appliance.
## PAN-125410
Fixed an issue where a new GPRS tunneling protocol version 2 control plane (GTPv2-C) session reused GTP-C tunnel parameters within two seconds after deleting the old GTP-C session, which caused a session conflict on the firewall.
## PAN-124893
Fixed an issue where a race condition caused the FIB entry list to form a circle, which in turn caused a process (mprelay) to infinitely loop.
## PAN-124039
A fix was made to address an issue where the GlobalProtect Portal feature in PAN-OS did not set a new session identifier after a successful user login ([CVE-2020-1993](https://security.paloaltonetworks.com/CVE-2020-1993)).
## PAN-123637
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where configuring 1G small form-factor pluggable (SFP) ports on a firewall with forced speed mode (of 1G) enabled made the link unusable when forced speed mode (of 1G) was also enabled on the peer firewall.
## PAN-122408
```caveat
PA-7000b Series firewalls with LFC cards only
```
Fixed an issue where the system logs would continuously report a failure to connect to the proxy for WildFire even when the connectivity was working properly.
## PAN-119806
Fixed an issue in an HA configuration where the dataplane restarted due to internal packet path monitoring failure on the passive firewall.
## PAN-116480
Fixed an issue in Panorama where the show system search-engine-quota CLI command, the show log-collector serial-number <log-collector_SN> CLI command, and **Statistics** (**Panorama > Managed Collectors > Statistics**) showed incorrect log retention data.
## PAN-111611
Fixed an issue where the connection between the firewall and Cortex Data Lake flapped if connections decreased.
## PAN-88136
Fixed a rare issue where a URL update caused the dataplane to restart.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 9.0.9-h1
---
## PAN-150172
Fixed an issue where dataplane processes restarted when attempting to access websites that had the NotBefore attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
@@ -0,0 +1,441 @@
---
type: Addressed
product: PAN-OS
version: 9.0.9
---
## WF500-5320
Fixed an issue where the WF-500 cluster did not synchronize verdicts after successful verdict recheck queries with the WildFire global cloud.
## PAN-148988
A fix was made to address a Security Assertion Markup Language (SAML) authentication issue ([CVE-2020-2021](https://security.paloaltonetworks.com/CVE-2020-2021)).
## PAN-148068
Fixed an issue where SSL connections were blocked if you enabled decryption with the option to block sessions that have expired certificates. This issue included servers that sent an expired AddTrust certificate authority (CA) in the certificate chain.
## PAN-145195
```caveat
and PAN-145149
```
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
## PAN-145151
```caveat
and PAN-145149
```
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
## PAN-145150
```caveat
and PAN-145149
```
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
## PAN-145026
Fixed an issue where Cortex Data Lake certificates on the firewall were not automatically renewed after the certificates expired.
## PAN-144882
Fixed an issue where the firewall generated critical system logs: Fsck failed for Logging Raid Disk Pair after downgrading from PAN-OS 9.0 to PAN-OS 8.1.
## PAN-144782
Fixed an issue where a configuration audit created a large number of opresult.out files, which filled up the session/pan/user_tmp directory in opt/pancfg. This caused a slow Panorama response until a device restart was performed or the files were manually deleted from the root of the device.
## PAN-144646
Fixed an issue where a process (varrcvr) stopped responding on the PA-7000 Series Log Forwarding Card (LFC) when it received a verdict from the WildFire cloud.
## PAN-143957
Fixed an issue where, after loading a saved configuration snapshot by API, a custom role-based administrator required Superuser privileges to perform a full commit.
## PAN-143648
```caveat
VM-Series firewalls in Azure environment only
```
Fixed an issue where a kernel panic in a Linux Integration Services (LIS) driver caused the firewall to reboot by itself.
## PAN-141563
Fixed an issue where Slot 8 path monitoring failure occurred due to a memory buildup in a process (logrcvr) that was caused by slow communication and connection between log forwarding and Cortex Data Lake.
## PAN-140846
Fixed an issue where the dataplane restarted during a commit when **Netflow** was enabled.
## PAN-140494
Added a mechanism to detect corrupted or incorrect formats received on dataplane CPU. Such packets are dropped, and a counter, pkt_recv_bad_group, is incremented.
## PAN-140465
```caveat
VM-Series firewalls only
```
Fixed connection issues between IPv6 peers when the IPv6 neighbor cache was synchronized in an HA cluster where, after failover, the newly active firewall did not send multicast neighbor solicitation from its global unicast address.
## PAN-140386
Fixed an intermittent issue where the firewall used IP addresses instead of domain names for URL category lookup after upgrading to 9.0.6.
## PAN-139935
Fixed an issue in the URL process where a process (devsrvr) stopped responding.
## PAN-139764
Fixed an issue where an out-of-memory (OOM) condition occurred due to a memory leak, which caused a process (configd) to restart.
## PAN-139718
Fixed an issue where the firewall failed stateful inspection for GTP forward relocation requests greater than 1,500 bytes and could not parse Access Point Name (APN) information in forward relocation requests.
## PAN-139587
```caveat
PA-5200 Series and PA-7000 Series firewalls only
```
Fixed an issue where high and continuous CPU utilization was seen on dataplanes after IPSec Encapsulating Security Payload (ESP) rekeying occurred for multiple tunnels.
## PAN-139391
Fixed an issue where unique GlobalProtect portal profiles were not selected in the correct order.
## PAN-138870
Fixed an issue where a process (configd) restarted and administrators received one of the following error messages: Timed out while getting config lock. Please try again or Please wait while the server reboots... due to a database error.
## PAN-138813
Fixed a performance drop issue seen when using API to configure larger sets of objects (more than 25 objects).
## PAN-138739
Fixed an issue where, in a high availability (HA) active/active configuration in a virtual wire deployment with asymmetric traffic, decryption did not work for some sites.
## PAN-138476
Fixed an intermittent issue where logs were delayed or missing when querying for logs by applying filters. To leverage this fix, you must upgrade Panorama to 9.0.9 and the Cloud Services plugin to 1.6.0-h1.
## PAN-137966
Fixed a configuration lock issue where Panorama timed out due to a process (configd) being unable to read another process (mongod).
## PAN-137902
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where hot swapping a PA-7000 100G NPC with a PA-7000 20G NPC caused packet buffer leak and slot restarts.
## PAN-137867
```caveat
PA-7000 Series firewalls only, running with both a PA-7000 100G NPC and a PA-7000 20G NPC
```
Fixed an issue where IPSec traffic caused dataplane restarts.
## PAN-137387
Fixed an issue where URL filtering used the IP address instead of the hostname, which led to incorrect URL categorization.
## PAN-137138
Fixed an issue where a process (configd) consistently restarted with the following error message: virtual memory limit exceeded, restarting due to a dynamic updates push from Panorama to multiple firewalls.
## PAN-136703
```caveat
PA-3000 Series and PA-800 Series firewalls only
```
Fixed an issue with insufficient memory allocation for configurations to accommodate the PAN-OS 9.0 Dynamic Address Group feature.
## PAN-136649
Fixed an issue where PA-7000 20GXM and PA-7000 20GQXM Network Processing Cards (NPCs) failed to process some sessions for Layer 7 inspection due to internal maximum threshold value that was not set.
## PAN-136608
Fixed an issue in Panorama where the Security policy **Target** displayed the serial number of the targeted device instead of the hostname.
## PAN-136390
```caveat
PA-7000 Series with 100GB NPC only
```
Fixed an issue during firewall bootup where the following error message: Bootloader upgrade failed, ret 255 appeared when small form-factor pluggable (SFP) modules were installed.
## PAN-135865
Fixed an issue that prevented Panorama from being switched out of management-only mode when deployed in Amazon Web Services (AWS) instance types M5 and C5.
## PAN-135684
Fixed an issue with log collectors on Panorama where large index sizes caused higher CPU usage than expected when disk space usage was high.
## PAN-135587
Fixed an issue where the GlobalProtect gateway was unable to parse a large list of IP addresses assigned on a local machine.
## PAN-135039
Fixed an issue in Panorama where a memory leak occurred during an HA sync commit.
## PAN-134309
Fixed an issue where a process (devsrvr) restarted when it hit the limit of the number of custom patterns available in the allocated memory.
## PAN-133731
Fixed an issue on the Panorama Virtual Appliance where the show interface all CLI command did not list any output.
## PAN-133727
Fixed an issue where Session Initiation Protocol (SIP) messages were not parsed correctly when the packet was received in separate segments, which caused the receiver to receive corrupted messages.
## PAN-133614
Fixed an issue on the Panorama Virtual Appliance where SNMP Object IDs (OIDs) were missing for interfaces other than the **Management** interface.
## PAN-133495
Fixed an issue where the Terminal Server (TS) Agent disconnected on the firewall after a failover or reboot.
## PAN-133411
Fixed an issue where after making configuration changes and selecting **Preview Changes**, a 500 Internal Server Error message displayed due to a memory leak.
## PAN-133211
Fixed an issue where the policy order was not maintained when moved to a different device group.
## PAN-132995
```caveat
PA-7000 Series and PA-3200 Series firewalls only
```
Fixed an issue where when jumbo frames were enabled, the maximum transmission unit (MTU) size limit was lower than expected.
## PAN-132766
Fixed an issue in Panorama where custom region objects were not visible in the GlobalProtect Portal **External Gateway** drop-down.
## PAN-132712
Fixed an issue where scheduled reports did not run on a PA-7000 Series firewall not managed by Panorama after upgrade to 8.1.10 or 9.0.4 and later versions.
## PAN-132476
Made improvements to the log storage for VM-Series for NSX Panorama.
## PAN-131945
Fixed an issue where **Device > VM-Series** on the firewall web interface showed a blank screen.
## PAN-131792
Fixed an issue where the **Name** log filter (**Monitor > Logs > Traffic**) was not maintained when viewing the **Log Viewer** for a Security policy rule (**Policies > Security**) from the drop-down.
## PAN-131501
Fixed an issue when configuring Clientless VPN and executing the portal-getconfig CLI command where user groups were retrieved but were not freed, which caused a memory leak on a process (sslvpn).
## PAN-131290
Fixed an issue where reports from Panorama displayed the following messages: Please wait... and Warning: Some of the devices are in High Speed Log Forwarding Mode.
## PAN-131038
Fixed an issue on the firewalls where the FIB lookup routing test did not display all available paths on the web interface.
## PAN-130870
Fixed an issue where the management plane CPU on the firewall was high due to index generation on summary logs.
## PAN-130776
Fixed an issue on Panorama where Applications and Threats content update deployment failed due to the content version date check.
## PAN-130558
Fixed an issue on the firewalls where SNMP queries for panZoneTable listed details for only one zone when there were two zones with same names under different virtual systems.
## PAN-130121
Fixed an issue in Amazon Web Services (AWS) where Ethernet1/1 failed DHCP renewal after the hour.
## PAN-129281
Fixed an issue where a process (useridd) restarted due to a buffer overflow when the time-to-live (TTL) and **Idle Timeout** values were set to **Never**, a timing issue between user group context and a process (sysd) callback, and a group mapping issue when multiple group mappings fetched the same groups with different override domains.
## PAN-128879
Fixed an issue where the PAN-OS XML API inject was not working for IP address to user mappings or for the import of software, content, and plugins.
## PAN-128393
Fixed an issue where User-ID running on port 5007 responded with the default certificate and participated in mutual authentication after upgrading to PAN-OS 9.0, which exposed the default certificate on the firewall to third-party vulnerability scanners.
## PAN-128155
Fixed an issue where system log entries misspelled "client version" as "lient version", which made it difficult for syslog servers to find these entries.
## PAN-128078
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
## PAN-127434
Fixed an issue where reports for URLs were not generating the correct data output.
## PAN-127375
Fixed an issue where a process (rasmgr) restarted multiple times, which caused the firewall to reboot.
## PAN-127260
Fixed an issue where the /opt/pancfg partition became full due to a large amount of botnet reports that were not automatically deleted.
## PAN-125524
Fixed an issue where the dataplane restarted when many NAT rules were followed by successive commits.
## PAN-125501
Fixed an issue where URL information in a URL **Custom Report** was blank when the report contained flexible size fields (such as **URL Category List**).
## PAN-125466
Fixed an issue where, during Antivirus or Threat Content update downloads or install, some show commands in the CLI, API calls, and web interface pages gave information output with significant delay (15-60 seconds).
## PAN-124916
Added two ciphers for GlobalProtect Portal TLS connections.
## PAN-123279
Fixed an issue where a process (configd) stopped responding after upgrading Panorama to 8.1.9 from 8.0.16 due to 8.0 WildFire appliance register requests.
## PAN-123090
```caveat
PA-3000 Series firewalls only
```
Fixed an issue where a configuration commit failed due to a memory allocation failure on the dataplane.
## PAN-122226
Fixed an issue where traffic failed to match Security policies using wildcard address objects.
## PAN-121602
Fixed an issue on Panorama where a query (after-change-preview contains) did not return the expected results for configuration logs.
## PAN-120830
Fixed an issue in Panorama where certificate import failed with the following error message: Certificate chain cannot be validated, required CAs not found.
## PAN-120614
Fixed an issue where a commit from a Panorama appliance running PAN-OS 9.1 to a managed firewall running PAN-OS 9.0 or earlier failed with the following error message in ms.log: error generating tranform ike-pre-transform.xsl.
## PAN-120454
Fixed an issue where the firewall did not fail over to the secondary LDAP server when the primary LDAP server was not reachable and the configured LDAP bind timeout was not properly honored when SSL protocol was used.
## PAN-120113
Fixed an issue where the **to**, **from**, and **subject** fields did not populate in the threat logs if the fields were out of order.
## PAN-120105
Fixed an issue where email header information intermittently was not present in threat logs.
## PAN-119645
Fixed an issue where a process (panio) used unnecessary memory and caused an out-of-memory (OOM) condition on the dataplane if the dataplane was already low on memory.
## PAN-119170
Fixed an issue where Panorama did not display managed devices when selecting **Revert Content** (**Panorama > Device Deployment > Dynamic Updates**).
## PAN-119159
Fixed an issue where if one invalid FQDN object was configured, FQDN resolution failed for all FQDN objects.
## PAN-118098
Fixed an issue where a process (useridd) restarted while updating user groups. This issue occurred when multiple group mapping profiles were used to fetch the same group information while using different domain override settings.
## PAN-117606
Fixed an issue where a process (configd) crashed while making configuration changes on Panorama.
## PAN-117487
Fixed an issue where a process (mgmtsrvr) stopped responding due to a memory corruption issue when acquiring a configuration lock.
## PAN-117075
Fixed an issue where the firewall did not process the TLS record in SSL Inbound Inspection as expected, which introduced out-of-order packets in the transmit stage packet capture and affected client performance while accessing HTTP video applications.
## PAN-116835
Fixed an issue with log reading performance when using WMI for server monitoring with PAN-OS integrated User-ID agent.
## PAN-116720
A fix was made to address a reflected cross-site scripting (XSS) vulnerability in the PAN-OS management web interface where, if a remote attacker was able to convince an administrator with an active authenticated session on the firewall management interface to click on a crafted link, the attacker could execute arbitrary code JavaScript code in the administrator's browser and perform administrative actions ([CVE-2020-2036](https://security.paloaltonetworks.com/CVE-2020-2036)).
## PAN-115914
Fixed an issue where Static, Connected, and Host routes were missing on the FIB table of the firewall in a passive state after 300 seconds of switch over.
## PAN-112120
Fixed an issue where threat **Name** field of a threat **Custom Report** displayed the threat ID instead of the threat name.
## PAN-111379
Fixed an issue on the firewall where the Application Command Center (ACC) **Network Activity** tab displayed the message In Progress and stopped responding.
## PAN-110457
Fixed an issue where Panorama ran out of memory due to high memory usage on a process (configd).
## PAN-106763
Fixed an issue where the dataplane crashed while freeing up memory due to a corrupted or long certificate field in the handshake.
## PAN-102202
Fixed an issue where the OSPF summary Link State Advertisement (LSA) for the default 0.0.0.0/0 route were not advertised by the Area Border Router (ABR).
## PAN-98933
Fixed an issue on an M-Series appliances in a high availability (HA) active/passive configuration where the schedules (*Device > Dynamic Updates*) were unresponsive after a failover or restart of Panorama.
## PAN-98694
Fixed an issue on a PA-5200 Series firewall in an HA active/passive configuration where the firewall dropped TCP-FIN packets after a failover.